HTTP: Progress Telerik Report Server Potential Authentiction Bypass

This signature detects attempts to exploit a known vulnerability against Progress Telerik. A successful attack can lead to Authentiction bypass.

Extended Description

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

Affected Products

Telerik report_server_2024

References

CVE: CVE-2024-4358

Short Name
HTTP:CTS:PROGRES-TELERIK-BYPASS
Severity
Critical
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Authentiction Bypass CVE-2024-4358 Potential Progress Report Server Telerik
Release Date
05/02/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3805
False Positive
Rarely
Vendors

Telerik

Found a potential security threat?