CVE-2024-28140: Violation of Least Privilege Principle

0.0 CVSS

Description

The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.

Classification

CVE ID: CVE-2024-28140

CVSS Base Severity: LOW

CVSS Base Score: 0.0

Affected Products

Vendor: Image Access GmbH

Product: Scan2Net

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://r.sec-consult.com/imageaccess
https://www.imageaccess.de/?page=SupportPortal&lang=en

Timeline