CVE-2024-51961
CVSS 3.1 Score 7.5 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity none
Availability none
Scope unchanged
Privileges Required none
Details
Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 610
CWE ID 73
Summary
CVE-2024-51961 is a local file inclusion vulnerability in ArcGIS Server versions 10.9.1 to 11.3. This issue allows unauthenticated attackers to craft malicious URLs that can potentially disclose sensitive configuration information by reading internal files from the remote server. Due to the nature of the files that could be accessed, the impact to confidentiality is high, while there is no reported impact on the integrity or availability of the affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Esri