CVE-2024-25699 is a difficult-to-exploit improper authentication vulnerability affecting Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes. This high-severity vulnerability (CVSS 8.5) allows a remote, low-privileged authenticated attacker to bypass authentication and authorization boundaries, potentially compromising the confidentiality, integrity, and availability of the software. While the attack complexity is high, successful exploitation could lead to a significant scope change. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.8.1, <= 11.2CPE matchmatch criteria | cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:* | ||
<= 11.1CPE matchmatch criteria | cpe:2.3:a:esri:arcgis_enterprise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.