CVE-2024-6049CWE-32

Unauthenticated Path Traversal

High · published October 24, 2024

CVSS v3.1
7.5
EPSS
4%
Percentile
90.4
In the wild
Unconfirmed
What it is

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.04235 · 90.4th percentile
Weakness
CWE-32 · Path Traversal: '...' (Triple Dot)
Published
2024-10-24T07:47Z
EPSS history
Timeline
  • 24 OCT 07:47Z
    Unauthenticated Path Traversal
    cvelistv5