Vulnerability record · CVE-2024-4358 · published 29 May 2024
CVE-2024-4358: Progress Telerik Report Server authentication bypass via spoofing
Telerik · Report Server 2024
Telerik Report Server 2024 Q1 (10.0.24.305) and earlier on IIS contains an authentication bypass by spoofing (CWE-290). An unauthenticated remote attacker can reach restricted functionality without valid credentials, exposing administrative features of the reporting platform.
Description
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, KEV listing and near-maximum EPSS makes this an urgent patch target.
What it is
Telerik Report Server 2024 Q1 (10.0.24.305) and earlier on IIS contains an authentication bypass by spoofing (CWE-290). An unauthenticated remote attacker can reach restricted functionality without valid credentials, exposing administrative features of the reporting platform.
Impact
An attacker gains access to restricted Report Server functionality without authenticating, which can lead to data exposure and further compromise of the host or connected reporting data.
Attack surface
Reachable over the network via HTTP on IIS; the CVSS vector shows no privileges and no user interaction required, so any exposed instance is directly attackable.
Exploitation
Listed in CISA KEV with a 2024-06-13 addition and a 2024-07-04 remediation due date, and EPSS 30-day probability is 0.97482 (99.9th percentile), indicating active exploitation. No ransomware campaign use is recorded.
What to do
- Apply the vendor mitigation or fixed build per the Telerik Report Server knowledge base advisory for CVE-2024-4358.
- If patching is not possible, take the instance off the public internet or discontinue use as CISA directs.
- Restrict network access to the Report Server IIS endpoint to trusted management networks only.
- Review Report Server accounts, scheduled tasks and configuration for unauthorized changes made before remediation.
- Monitor vendor advisories for updated fixed versions covering 2024 Q1 and earlier.
Detection
- Audit IIS and Report Server logs for requests to restricted or administrative endpoints that succeed without a prior authentication event.
- Alert on access to Report Server management paths from unexpected source IPs or user agents.
- Correlate Report Server activity with outbound connections or file writes that suggest post-exploitation.
- Hunt for new or modified Report Server users, roles or scheduled tasks created outside change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4358 to the Known Exploited Vulnerabilities catalog on 13 June 2024 as "Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 July 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 | MitigationVendor Advisory |
| https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4358 | US Government Resource |
Track CVE-2024-4358 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4358), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.