Path traversal in Endpoint Manager - CVE-2024-50329

 

Path traversal in Endpoint Manager - CVE-2024-50329

Published: November 15, 2024 / Updated: November 18, 2024


Vulnerability identifier: #VU100557
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-50329
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick the victim into uploading a specially crafted file and overwrite arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

Endpoint Manager

How to mitigate CVE-2024-50329

Install update from vendor's website.

Endpoint Manager - addressed in versions 2022 SU6 November Update, 2024 November Update

External References

Related Security Bulletins