CVE-2024-6364

A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:persistence:*:*:*:*:*:*:*:*

History

15 Jul 2025, 16:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4
First Time Absolute
Absolute persistence
CPE cpe:2.3:a:absolute:persistence:*:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad en las versiones de Absolute Persistence® anteriores a la 2.8 cuando no está activada. Esto podría permitir que un atacante experto con acceso físico al dispositivo y control total de la red hostil inicie comandos del sistema operativo en el dispositivo. Para solucionar esta vulnerabilidad, actualice el firmware del dispositivo a la última versión disponible. Para obtener instrucciones de actualización, póngase en contacto con el fabricante del dispositivo o con Absolute Security (consulte la referencia a continuación).
References () https://www.absolute.com/platform/vulnerability-archive/cve-2024-6364 - () https://www.absolute.com/platform/vulnerability-archive/cve-2024-6364 - Vendor Advisory

13 May 2025, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.absolute.com/platform/vulnerability-archive/CVE-2024-6364', 'source': 'SecurityResponse@netmotionsoftware.com'}
  • () https://www.absolute.com/platform/vulnerability-archive/cve-2024-6364 -
CWE CWE-284

13 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 17:15

Updated : 2025-07-15 16:24


NVD link : CVE-2024-6364

Mitre link : CVE-2024-6364

CVE.ORG link : CVE-2024-6364


JSON object : View

Products Affected

absolute

  • persistence
CWE
CWE-284

Improper Access Control