Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6049

Опубликовано: 24 окт. 2024
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

EPSS

Процентиль: 99%
0.68338
Средний

7.5 High

CVSS3

Дефекты

CWE-32

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

EPSS

Процентиль: 99%
0.68338
Средний

7.5 High

CVSS3

Дефекты

CWE-32