CVE-2024-22074 describes an Incorrect Access Control vulnerability in multiple versions of Dynamsoft Service, affecting versions 1.8.1025 through 1.8.2013 and several earlier series. This critical vulnerability, rated 9.8 CVSS, allows an unauthenticated attacker to achieve high confidentiality, integrity, and availability impacts over the network with low attack complexity. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 80/100 indicates significant potential danger. Organizations using affected Dynamsoft Service versions should prioritize upgrading to patched versions 1.8.2014, 1.7.4212, or later as soon as possible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.516, < 1.3.3212CPE matchmatch criteria | cpe:2.3:a:dynamsoft:dynamsoft_service:*:*:*:*:*:*:*:* | ||
>= 1.4.1230, < 1.4.3212CPE matchmatch criteria | cpe:2.3:a:dynamsoft:dynamsoft_service:*:*:*:*:*:*:*:* | ||
>= 1.5.0625, < 1.5.31212CPE matchmatch criteria | cpe:2.3:a:dynamsoft:dynamsoft_service:*:*:*:*:*:*:*:* | ||
>= 1.6.0428, < 1.6.3212CPE matchmatch criteria | cpe:2.3:a:dynamsoft:dynamsoft_service:*:*:*:*:*:*:*:* | ||
>= 1.7.0330, < 1.7.4212CPE matchmatch criteria | cpe:2.3:a:dynamsoft:dynamsoft_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.