The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.
History

Mon, 14 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 14 Oct 2024 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Heimavista
Heimavista epage
Heimavista rpage
CPEs cpe:2.3:a:heimavista:epage:*:*:*:*:*:*:*:*
cpe:2.3:a:heimavista:rpage:*:*:*:*:*:*:*:*
Vendors & Products Heimavista
Heimavista epage
Heimavista rpage
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Oct 2024 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-14T06:12:23.993Z

Reserved: 2024-03-13T02:04:03.661Z

Link: CVE-2024-2412

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.516Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-13T03:15:06.577

Modified: 2024-11-21T09:09:41.943

Link: CVE-2024-2412

cve-icon Redhat

No data.