CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-45718: Sensitive data disclosure vulnerability

4.6 CVSS

Description

Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a low- privileged account is required to access the configuration file containing the sensitive data.

Classification

CVE ID: CVE-2024-45718

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.6

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Affected Products

Vendor: SolarWinds

Product: Kiwi Syslog NG

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.94% (scored less or equal to compared to others)

EPSS Date: 2025-03-12 (when was this score calculated)

References

https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45718
https://documentation.solarwinds.com/en/success_center/kss/content/release_notes/kssng_1-3-1_release_notes.htm

Timeline