Protection Mechanism Failure in RevoWorks SCVX and RevoWorks Browser - CVE-2024-25091
Published: February 29, 2024
Vulnerability identifier: #VU86921
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25091
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. An attacker can bypass implemented security restrictions and elevate privileges on the system.
Affected software
RevoWorks SCVX
RevoWorks Browser
RevoWorks Browser
How to mitigate CVE-2024-25091
Install updates from vendor's website.
RevoWorks SCVX - update to scvimage4.10.21_1013
RevoWorks Browser - update to 2.2.95
RevoWorks Browser - update to 2.2.95