CVE-2024-11482 CRITICAL

CVE-2024-11482

Vendor Trellix
Product Trellix Enterprise Security Manager (ESM)
Weakness CWE-78
Published November 29, 2024
Last update March 18, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

Key dates

02Disclosure timeline

November 29, 2024 CVE published
March 18, 2025 Record updated