VDB
CVE-2024-56337
CVE-2024-56337
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. The previous mitigation for CVE-2024-50379 was incomplete, permitting an RCE on case insensitive file systems when the default servlet is enabled for write
EPSS 9.03% · 94.8th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
EPSS Score
9.03%
94.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH APROL <R 4.4-01P5 |
Timeline
- Dec 20, 2024 CVE Published
- Dec 20, 2024 Coalition ESS Score
- Dec 21, 2024 EPSS Score
- Dec 31, 2024 Coalition ESS Score
- Jan 20, 2025 Coalition ESS Score
- Mar 19, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 13, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 16, 2025 EPSS Score
References
- https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P011-661853b7.pdf advisory
- https://psirt.abb.com/csaf/2026/sa26p011.json advisory
- https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-56337 advisory