Junglewise Threat Intelligence

CVE-2024-55402: 4C Strategies Exonaut improper access control

CVE-2024-55402 · Severity: medium · CVSS 5.3 · Published 2025-08-06

Technologies: 4C Strategies Exonaut.

Executive brief

4C Strategies Exonaut, a software suite used for organizational resilience, training, and crisis management, contains a security flaw in its access control mechanisms. This vulnerability could allow unauthorized individuals to access certain information without proper permission. An exploit could lead to the exposure of sensitive organizational data, potentially impacting strategic planning or crisis response operations.

Technical details

An improper access control vulnerability (CWE-284) exists in 4C Strategies Exonaut versions prior to 22.4 and 21.6.2.1-1. The flaw allows a remote attacker to bypass intended access restrictions via the network without requiring authentication or user interaction. Successful exploitation enables the attacker to read sensitive information (Confidentiality impact), though it does not appear to allow for data modification or service disruption based on the reported CVSS vector. The vendor has confirmed the issue and released patches in versions 22.4 and 21.6.2.1-1.

Affected products

  • 4C Strategies Exonaut before 22.4, before 21.6.2.1-1

Timeline

  • 2025-08-05: disclosed: Vulnerability discovered by Justin Hocquel and gist created.
  • 2025-08-06: advisory: CVE published by NVD/MITRE.
  • 2025-08-06: patched: Vendor confirmed fix in versions 22.4 and 21.6.2.1-1.

References