CVE-2024-28139: Image Access GmbH SCAN2NET
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
Affected products
- Image Access GmbH SCAN2NET: up to and including 7.42B
Published 2024-12-11. Last modified 2026-06-17.