CVE-2024-13026 – “Algo Edge Navify Algorithm Suite Authentication Token Manipulation”

The following table lists the changes that have been made to the
CVE-2024-13026 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 5cdcf916-2b10-4ec8-bfc1-d054821e439e

    Jan. 17, 2025

    Action Type Old Value New Value
    Added Tag unsupported-when-assigned
    Added Description A vulnerability exists in Algo Edge up to 2.1.1 – a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.
    Added CVSS V4.0 AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:D/RE:L/U:Clear
    Added CWE CWE-326
    Added Reference https://diagnostics.roche.com/content/dam/diagnostics/Blueprint/en/pdf/Algo%20Edge%20-%20Authentication%20Vulnerability%20-%20Product%20Security%20Advisory.pdf
Share the Post:

Related Posts