A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34063 A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Oct 2025 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Trellix
Trellix enterprise Security Manager
CPEs cpe:2.3:a:trellix:enterprise_security_manager:11.6.10:*:*:*:*:*:*:*
Vendors & Products Trellix
Trellix enterprise Security Manager

Wed, 19 Mar 2025 00:45:00 +0900

Type Values Removed Values Added
References

Fri, 29 Nov 2024 23:15:00 +0900

Type Values Removed Values Added
First Time appeared Hp
Hp enterprise Security Manager
CPEs cpe:2.3:a:hp:enterprise_security_manager:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp enterprise Security Manager
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 16:45:00 +0900

Type Values Removed Values Added
Description A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2025-03-18T14:56:37.259Z

Reserved: 2024-11-20T05:16:00.690Z

Link: CVE-2024-11482

cve-icon Vulnrichment

Updated: 2025-03-18T14:56:37.259Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-29T08:15:04.437

Modified: 2025-10-28T18:34:25.197

Link: CVE-2024-11482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses