S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 6, 2026

CVE-2024-49357 Scanner

CVE-2024-49357 Scanner - Information Disclosure vulnerability in ZimaOS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-49357
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/system.json`, expose sensitive data like installed applications and system information without requiring any authentication or authorization. This sensitive data leak can be exploited by attackers to gain detailed knowledge about the system setup, installed applications, and other critical information. As of time of publication, no known patched versions are available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ZimaOSby IceWhaleTech
<= 1.2.4
zimaosby icewhaletech
0
Updated Sep 10, 2026View on NVD →
Detail

ZimaOS is a fork of CasaOS, specifically designed for Zima devices and x86-64 systems with UEFI. It is an operating system utilized by developers and users who need a robust OS for these devices. ZimaOS offers a user-friendly interface and a suite of applications tailored for seamless integration. Its versatility and customization options make it a preferred choice in these environments. However, maintaining its security is crucial, given the sensitivity of systems it operates on.

The detected vulnerability in ZimaOS, specifically in versions up to 1.2.4, involves the unintended exposure of sensitive data through certain API endpoints. This information disclosure vulnerability does not require any authentication, allowing unrestricted access to critical data. Such vulnerabilities can pose significant risks if exploited by malicious actors. The lack of authorization checks exacerbates the severity, making it imperative to address this flaw promptly.

Technically, the vulnerability arises from API endpoints designed to serve sensitive information about the system and installed applications. Vulnerable endpoints include `http:///v1/users/image?path=/var/lib/casaos/1/app_order.json` and similar paths that should be secured. These endpoints inadvertently allow any user to access detailed system configurations and application data without authentication or authorization. This unrestricted access can provide an attack vector for further intrusion activities.

If exploited, this vulnerability could allow attackers to gather significant intelligence about the target system. Such information can aid in planning further attacks, potentially allowing adversaries to exploit other vulnerabilities or gain more profound access. The exposure of system and app data might also lead to privacy breaches and compromise of sensitive data, affecting both personal and organizational security.

REFERENCES

Solution Advice
  • Upgrade ZimaOS to version 1.2.5 or later to mitigate the identified risk.
  • Implement proper access controls to restrict unauthorized access to sensitive APIs.
  • Regularly audit and monitor API endpoints for unusual access patterns or discrepancies.
  • Educate users and system administrators about secure data handling practices.
  • Review and update security settings in accordance with best practices and evolving threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.