SolarWinds Kiwi CatTools Sensitive Data Disclosure via Non-Default Troubleshooting Setting
CVE-2024-45713 Published on October 17, 2024

SolarWinds Kiwi CatTools Sensitive Information Disclosure Vulnerability
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been enabled for troubleshooting purposes.

NVD

Vulnerability Analysis

CVE-2024-45713 can be exploited with local system access, requires user interaction and user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.


Products Associated with CVE-2024-45713

Want to know whenever a new CVE is published for SolarWinds Kiwi Cattools? stack.watch will email you.

 

Affected Versions

SolarWinds Kiwi CatTools Version Kiwi CatTools 3.12 and previous versions is affected by CVE-2024-45713

Exploit Probability

EPSS
0.07%
Percentile
22.27%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.