CVE-2024-0563

EUVD-2024-16356
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
M-Files CorporationCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
m-filesm-files_server
𝑥
< 23.2.12340.6
m-filesm-files_server
23.2.12340.6 <
𝑥
< 23.8.12892.6
m-filesm-files_server
23.2.12340.6 ≤
𝑥
< 23.8.12892.17
m-filesm-files_server
23.8.12892.6 <
𝑥
< 24.2.13421.8
𝑥
= Vulnerable software versions