CRITICAL
CVE-2024-4358
CVSS
9.8
KEV
Description
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Summary dbcve.org
In Progress Telerik Report Server versions 2024 Q1 (10.0.24.305) and earlier running on IIS contains an authentication bypass vulnerability that allows unauthenticated attackers to access restricted server functionality without valid credentials.
Mitigation
Apply vendor patches to upgrade Telerik Report Server beyond version 10.0.24.305. If immediate patching is not feasible, implement network segmentation to limit exposure and review IIS authentication settings as a compensating control.
Weakness (CWE)
CWE-290
EPSS Score
97.48%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.