CVE-2024-1800 is a critical remote code execution (RCE) vulnerability affecting Progress Telerik Report Server versions prior to 2024 Q1 (10.0.24.130). This flaw stems from an insecure deserialization vulnerability, allowing authenticated attackers to execute arbitrary code on the server. With a CVSS score of 8.8 (HIGH), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available via a Metasploit module, and the vulnerability has garnered significant community attention and media coverage, including warnings from CISA.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.24.130CPE matchmatch criteria | cpe:2.3:a:progress:telerik_report_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.