CVE-2024-9334CWE-798CWE-921

Information Disclosure in E-Kent's Pallium Vehicle Tracking

High · published February 27, 2025

CVSS v3.1
8.2
EPSS
0%
Percentile
28.9
In the wild
Unconfirmed
What it is

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass.

This issue affects Pallium Vehicle Tracking: before 17.10.2024.

The record
Technical detail
CVSS v3.1
8.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00358 · 28.9th percentile
Weaknesses
CWE-798 · Use of Hard-coded Credentials; CWE-921 · Storage of Sensitive Data in a Mechanism without Access Control
Published
2025-02-27T13:54Z
EPSS history
Timeline
  • 27 FEB 13:54Z
    Information Disclosure in E-Kent's Pallium Vehicle Tracking
    cvelistv5