Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Aug 7, 2024

CVE-2024-34102

High
CVSS 9.8EPSS 94.3%CISA KEVPoC Available
Adobe/Commerce and Magento Open Source

Description

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

CVSS Score

9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS — Exploit Probability

94.3%

Higher than 100.0% of all CVEs

Weakness Classification (CWE)

CWE-611CWE-611MITRE

Required Action

https://helpx.adobe.com/security/products/magento/apsb24-40.html; https://nvd.nist.gov/vuln/detail/CVE-2024-34102

Risk Assessment

CRITICAL
In CISA KEV
Known exploit
Critical CVSS
High EPSS

Details

Severity
High
CVSS
9.8
EPSS
94.3%
CWE
CWE-611
Exploit
POC
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jul 17, 2024

Added to KEV

Jul 17, 2024

Remediation Due

Aug 7, 2024

Affected Product

Adobe

Commerce and Magento Open Source

View all Adobe CVEs