peter bassill · operator
$ cve CVE-2024-2056 JSON

CVE-2024-2056

9.8
CRITICAL · CVSS 3.1 · EPSS 16.7% (pctl 97)

Patch early

EPSS 16.7% — above the 10% action threshold.

Description

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS16.71% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-288
On CISA KEVno
Public exploitnone known
Published2024-03-05
Last modified2026-06-17

Affected (1)

VendorProduct
articatechartica proxy

References

→ the Explorer  ·  watch your stack  ·  NVD