Junglewise Threat Intelligence

CVE-2024-4358: Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

CVE-2024-4358 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-06-13

Vendors: Progress, Progress Software Corporation.

Executive brief

Progress Telerik Report Server contains an authentication bypass vulnerability via spoofing when hosted on IIS. An unauthenticated attacker can exploit this to gain unauthorized access to restricted functionality. This vulnerability has been observed being exploited in the wild.

Affected products

  • Progress Software Corporation Telerik Report Server 2024 Q1 (10.0.24.305) or earlier

Timeline

  • 2024-05-29: disclosed: CVE received from Progress Software Corporation and published by NVD
  • 2024-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-04: other: CISA remediation due date