Cyber Posture

CVE-2024-34520

High

Published: 12 February 2025

Published
12 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0004 11.4th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.

Security Summary

CVE-2024-34520 is an authorization bypass vulnerability (CWE-639) in the Mavenir SCE Application Provisioning Portal, specifically version PORTAL-LBS-R_1_0_24_0. It enables an authenticated guest user to circumvent client-side access controls and execute unauthorized administrative functions, such as the "add user" feature. The vulnerability carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant confidentiality, integrity, and availability impacts.

An attacker with guest-level authentication can exploit this vulnerability remotely over the network with low complexity and no user interaction required. By bypassing client-side restrictions, the attacker gains the ability to perform administrative actions beyond their privileges, potentially leading to full compromise of the portal's user management and other sensitive operations.

Advisories and further details are available in the referenced GitHub repository at https://github.com/whitewhale-dmb/Vulnerability-Research/tree/main/CVE-2024-34520, which contains vulnerability research materials. No specific patch or mitigation guidance is detailed in the provided CVE information.

Details

CWE(s)
CWE-639

References