CVE-2024-4358

Registration Authentication Bypass Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
April 30, 2024
Published Date
May 29, 2024
Last Updated
August 01, 2024
Vendor
Progress Software Corporation
Product
Telerik Report Server
Description
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2024-06-13 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-08-24 10:09:09 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-06-13 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

telerik_report_server_deserialization

Type: metasploit • Created: Unknown

Metasploit module for CVE-2024-4358

gh-ost00/CVE-2024-4358

Type: github • Created: 2024-08-24 10:09:09 UTC • Stars: 4

Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800

verylazytech/CVE-2024-4358

Type: github • Created: 2024-06-09 06:30:06 UTC • Stars: 12

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

Sk1dr0wz/CVE-2024-4358_Mass_Exploit

Type: github • Created: 2024-06-05 01:05:12 UTC • Stars: 24

RevoltSecurities/CVE-2024-4358

Type: github • Created: 2024-06-04 11:32:59 UTC • Stars: 5

An Vulnerability detection and Exploitation tool for CVE-2024-4358

sinsinology/CVE-2024-4358

Type: github • Created: 2024-06-03 08:22:10 UTC • Stars: 75

Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)