CVE-2024-4358

Confirmed PUBLISHED

Registration Authentication Bypass Vulnerability

Progress Software Corporation · Telerik Report Server
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 97.5%

At a Glance

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

nessus_scanner cisa nuclei_scanner metasploit
CVE Published
May 29, 2024
Exploitation Reported
Jun 13, 2024
CVSS
9.8 Critical
EPSS
97.5%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
progress_software
telerik_report_server

1.0.0.0 to < 10.1.24.514

Affected
Progress Software Corporation
Telerik Report Server

1.0.0 to < 10.1.24.514

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.