CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-48955

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.01815/1

CVE-2024-48955: Broken access control vulnerability in NetAdmin 4.030319 allows attackers to gain unauthorized access. This issue stems from unencrypted data transmission and lack of session authorization validation when assembling functionality menus. An attacker can exploit this by copying browser content from a user with elevated privileges, effectively impersonating them to access sensitive functionalities.

Despite a CVSS score of 0, indicating a seemingly low base severity, the presence of 'In The Wild' tag and a SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests some level of active exploitation or emerging risk. While not critical (SVRS above 80), CVE-2024-48955 poses a risk of privilege escalation. Organizations using NetAdmin 4.030319 should implement immediate session validation and encryption to prevent potential data breaches and unauthorized access.

In The Wild
2025-03-18

2024-10-29

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-48955 | NetAdmin 4.0.30319 improper authorization
vuldb.com2024-10-29
CVE-2024-48955 | NetAdmin 4.0.30319 improper authorization | A vulnerability was found in NetAdmin 4.0.30319. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization. This vulnerability is known as CVE-2024-48955. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
rss
forum
news

Social Media

No tweets found for this CVE

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://github.com/BrotherOfJhonny/CVE-2024-48955_Overview
[email protected]https://netadmin.software/gestao-de-identidade-e-acesso/
[email protected]https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-48955&sortby=bydate

CWE Details

CWE IDCWE NameDescription
CWE-384Session FixationAuthenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence