VYPR
Critical severity9.8NVD Advisory· Published Nov 29, 2024· Updated Jun 17, 2026

CVE-2024-11482

CVE-2024-11482

Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

Affected products

3
  • ESM/ESMllm-fuzzy
    Range: =11.6.10
  • cpe:2.3:a:trellix:enterprise_security_manager:11.6.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trellix:enterprise_security_manager:11.6.10:*:*:*:*:*:*:*
    • (no CPE)range: 11.6.12

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.