Executive brief
Progress Telerik Report Server contains an authentication bypass vulnerability via spoofing when hosted on IIS. An unauthenticated attacker can exploit this to gain unauthorized access to restricted functionality. This vulnerability has been observed being exploited in the wild.
Affected products
- Progress Software Corporation Telerik Report Server 2024 Q1 (10.0.24.305) or earlier
Timeline
- 2024-05-29: disclosed: CVE received from Progress Software Corporation and published by NVD
- 2024-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-04: other: CISA remediation due date