CVE-2024-6364 - CVE House
Back to Database
Status published Medium CVE-2024-6364

Server Identity Validation Bypass in Absolute Persistence®

Vulnerability Description

A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6364

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Denis Faiustov, GMO Cybersecurity by Ierae

Affected Vendor

Absolute Security

View all reports →

Affected Software

Absolute Persistence
Vulnerable Versions:
0

Timeline

Official Publish: May 13th, 2025
Last Modified: May 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.