Cyber Posture

CVE-2024-13173

High

Published: 08 January 2025

Published
08 January 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0017 38.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Security Summary

CVE-2024-13173 is a vulnerability in the health module stemming from insufficient restrictions on loading URLs, which can result in information leakage. It carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) and is associated with CWE-306 (Missing Authentication for Critical Function). The issue was published on 2025-01-08 and affects components within Vivo software, as detailed in the vendor's security advisory.

A remote, unauthenticated attacker can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation enables high-impact confidentiality violations, allowing the attacker to access sensitive information through unrestricted URL loading in the health module, while integrity and availability remain unaffected.

Vivo has published a security advisory providing details on the vulnerability at https://www.vivo.com/en/support/security-advisory-detail?id=14, which security practitioners should consult for recommended mitigations and patches.

Details

CWE(s)
CWE-306

References