PT-2025-9555 · Esri · Arcgis Server

CVE-2024-51954

·

Published

2025-02-18

·

Updated

2026-02-06

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ArcGIS Server versions 10.9.1 through 11.3
Description The issue is related to improper access control, which could allow a remote, low-privileged authenticated attacker to access secure services published on a standalone ArcGIS Server instance under unique circumstances. This could have a high impact on confidentiality, a low impact on integrity, and no impact on availability.
Recommendations For ArcGIS Server versions 10.9.1 through 11.3, consider restricting access to secure services until a fix is available. As a temporary workaround, review and enforce strict access controls on the ArcGIS Server instance to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02368
CVE-2024-51954

Affected Products

Arcgis Server