A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.
History

Tue, 13 May 2025 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 13 May 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 May 2025 17:45:00 +0000

Type Values Removed Values Added
References

Tue, 13 May 2025 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.
Title Server Identity Validation Bypass in Absolute Persistence®
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published: 2025-05-13T17:00:07.443Z

Updated: 2025-05-13T17:37:58.419Z

Reserved: 2024-06-26T22:42:45.308Z

Link: CVE-2024-6364

cve-icon Vulnrichment

Updated: 2025-05-13T17:37:50.739Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T17:15:50.850

Modified: 2025-05-13T19:35:18.080

Link: CVE-2024-6364

cve-icon Redhat

No data.