CVE-2024-2056 affects Artica Proxy, allowing services bound to the loopback interface, such as the root-privileged "tailon" service, to be accessed remotely through the proxy. This critical vulnerability (CVSS 9.8) has a network attack vector with low complexity, enabling unauthenticated attackers to view the contents of any file on the system. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for complete compromise of confidentiality, integrity, and availability is high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.50.000000CPE matchmatch criteria | cpe:2.3:a:articatech:artica_proxy:4.50.000000:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.