A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.
History

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.
Title Inadequate Encryption Strength Vulnerability in Roche Algo Edge
Weaknesses CWE-326
References
Metrics cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:N/R:A/V:D/RE:L/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Roche

Published:

Updated: 2025-02-12T20:31:25.559Z

Reserved: 2024-12-29T06:09:35.237Z

Link: CVE-2024-13026

cve-icon Vulnrichment

Updated: 2025-02-12T20:27:41.452Z

cve-icon NVD

Status : Received

Published: 2025-01-17T20:15:27.600

Modified: 2025-01-17T20:15:27.600

Link: CVE-2024-13026

cve-icon Redhat

No data.