CVE-2024-51954 Information
Mar 04, 2025
cve
Description
There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux which under unique circumstances could potentially allow a remote low privileged authenticated attacker to access secure services published a standalone (Unfederated)
ArcGIS Server instance. If successful this compromise would have a high impact on Confidentiality low impact on integrity and no impact to availability of the software.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Reference
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
LOW
Base Score
NONE
Base Severity
8.5
Share on: