CVE-2024-10660 is a critical SQL injection vulnerability affecting ESAFENET CDG 5, specifically within the deleteHook function of the HookService.java file. This flaw allows remote attackers to manipulate the hookId argument, leading to unauthorized database access and manipulation. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with no user interaction or privileges required, potentially resulting in complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, the exploit has been publicly disclosed, and its high EPSS score and significant community discussion (10 mentions) indicate a strong likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5CPE matchmatch criteria | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.