CVE-2024-6782 is a critical improper access control vulnerability affecting Calibre versions 6.9.0 through 7.14.0, allowing unauthenticated attackers to achieve remote code execution. This vulnerability has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. The EPSS score of 0.93876 indicates a very high likelihood of exploitation. Active exploitation is confirmed, with a Metasploit module and Nuclei templates publicly available, and it is being discussed within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Calibre | Calibre | >= 6.9.0, <= 7.14.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.