CVE-2024-41309
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Aug 7, 2024
Updated: Aug 8, 2024
CWE ID 284
Summary
CVE-2024-41309 is a newly disclosed vulnerability affecting the Hardware info module in IT Solutions Enjay CRM OS v1.0. This issue enables attackers to bypass the restricted terminal environment, granting them root-level access to the underlying system. Successful exploitation may lead to unauthorized system takeover, data theft, and potentially devastating consequences for the affected organization. The vulnerability poses a significant risk, particularly for those using the outdated CRM OS version, and urgent patching is recommended.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share