CVE-2024-57055 – WombatDialer Server-Side Access Control Bypass

The following table lists the changes that have been made to the
CVE-2024-57055 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 18, 2025

    Action Type Old Value New Value
    Added Description Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineering of the proprietary serialization protocol, making it difficult to exploit.
    Added Reference https://www.wombatdialer.com/blog/blog/2025/02/18/CVE/
Share the Post:

Related Posts