CVE-2024-46310 is a critical incorrect access control vulnerability in Cfx.re FXServer versions 9601 and earlier, allowing unauthenticated attackers to read and modify arbitrary user data through an exposed API endpoint. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network with no user interaction, leading to high confidentiality and integrity impacts. While there is no evidence of active exploitation, public exploit code (Nuclei templates) exists, and its high EPSS score indicates a significant probability of future exploitation, despite a lack of community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.