CVE-2024-22074: Dynamsoft Service
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, 1.7.4212, 1.6.3212, 1.5.31212, 1.4.3212, and 1.3.3212.
Affected products
- Dynamsoft Dynamsoft Service: from 1.0.516, before 1.3.3212 (fixed in 1.3.3212); from 1.4.1230, before 1.4.3212 (fixed in 1.4.3212); from 1.5.0625, before 1.5.31212 (fixed in 1.5.31212); from 1.6.0428, before 1.6.3212 (fixed in 1.6.3212); from 1.7.0330, before 1.7.4212 (fixed in 1.7.4212); from 1.8.1025, before 1.8.2014 (fixed in 1.8.2014)
Published 2024-06-06. Last modified 2026-06-17.