# CVE-2024-4358

## Summary

- **CVE ID:** CVE-2024-4358
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-290
- **Published:** May 29, 2024
- **Last Modified:** Oct 21, 2025

## Description

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

## Affected Products

- Progress Software Corporation — Telerik Report Server (1.0.0)

## References

- [CNA](https://docs.telerik.com/report-server/knowledge-base/registration-auth-bypass-cve-2024-4358)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4358)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 97.48%
- **EPSS Percentile:** 99.9

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jun 13, 2024
- **Due Date:** Jul 4, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._