Path traversal in Endpoint Manager - CVE-2024-34787

 

Path traversal in Endpoint Manager - CVE-2024-34787

Published: November 15, 2024 / Updated: November 18, 2024


Vulnerability identifier: #VU100539
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34787
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into uploading a specially crafted file and overwrite arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Endpoint Manager

How to mitigate CVE-2024-34787

Install update from vendor's website.

Endpoint Manager - addressed in versions 2022 SU6 November Update, 2024 November Update

External References

Related Security Bulletins