# CVE-2024-29837

## Summary

- **CVE ID:** CVE-2024-29837
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-284, CWE-1390
- **Published:** Apr 14, 2024
- **Last Modified:** Mar 13, 2026

## Description

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.

## Affected Products

- CS Technologies Australia — Evolution Controller (2.x)

## References

- [CNA](https://directcyber.com.au/sa/CVE-2024-29836-to-29844-evolution-controller-multiple-vulnerabilities.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 41.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._