CVE-2024-7292
EUVD-2024-4823609.10.2024, 15:15
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| progress | telerik_report_server | 𝑥 < 10.2.24.806 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| progress_software | telerik_report_server | 1.0.0.0 ≤ 𝑥 < 2024 Q3\/10.2.24.806\/ | ADP |