CRITICAL🇵🇱 Wersja polska

CVE-2024-45168

CVSS 9.1v3.1pub. 2024-08-22upd. 2025-09-03

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.

🤖 AI Analysis
How it works

The UCI IDOL 2 application transmits data via a raw socket without applying any authentication mechanism or verification of the identity of communication endpoints. The lack of access control (CWE-862) allows any entity on the network to connect to the communication channel and send or receive data without the need for any credentials. An attacker can thus impersonate an authorized endpoint or intercept an ongoing communication session.

Impact

An attacker can gain unauthorized access to transmitted data (breach of confidentiality) and manipulate communication — modify or inject data (breach of integrity). This enables man-in-the-middle attacks and takeover of the communication session.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. The manufacturer — UCI (uci.de) — has published relevant materials at https://uci.de/products/index.html. Until the fix is applied, network access to UCI IDOL 2 services should be restricted to trusted hosts only using a firewall or network segmentation.

Who is affected

UCI IDOL 2 (also known as uciIDOL or IDOL2) in versions up to 2.12 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Uci Idol2

    APP
    Uci
    ≤ 2.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-45166CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez błędną deserializację i przepełnienie bufora

CVE-2024-45167CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez improper input validation i deserializację

CVE-2024-45169CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez nieprawidłową deserializację i walidację danych

CVE-2024-45165MEDIUM5.3same product

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and ser...