CRITICAL

CVE-2024-4358

Telerik Report Server 2024 2024-05-29 CVSS v3.1
CVSS
9.8
KEV

Description

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

Summary dbcve.org

In Progress Telerik Report Server versions 2024 Q1 (10.0.24.305) and earlier running on IIS contains an authentication bypass vulnerability that allows unauthenticated attackers to access restricted server functionality without valid credentials.

Mitigation

Apply vendor patches to upgrade Telerik Report Server beyond version 10.0.24.305. If immediate patching is not feasible, implement network segmentation to limit exposure and review IIS authentication settings as a compensating control.

Weakness (CWE)

CWE-290

EPSS Score

97.48%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE