CVE-2024-9554 is an authorization bypass vulnerability affecting the Sovell Smart Canteen System up to version 3.0.7303.30513. Specifically, it resides in the Check_ET_CheckPwdz201 function within the suanfa.py file, which handles password resets. The vulnerability has a low CVSS score of 3.7, indicating a low severity. While it can be exploited remotely, the attack complexity is rated as high, and exploitation is considered difficult, with a potential impact of low integrity. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sovell | Smart Canteen System | 3.0.7303.30513CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.