CVE-2024-4358 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 97.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-07-04.
Description
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 97.48% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | yes — remediate by 2024-07-04 |
| Public exploit | yes |
| Published | 2024-05-29 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability |
|---|---|
| Added | 2024-06-13 |
| Due | 2024-07-04 |
| Vendor / product | Progress / Telerik Report Server |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| telerik | report server 2024 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass | 2025-03-28 |
References
→ the Explorer · watch your stack · NVD