Lucene search

K
cveHCLCVE-2024-23540
HistoryApr 03, 2024 - 5:15 p.m.

CVE-2024-23540

2024-04-0317:15:50
CWE-22
HCL
web.nvd.nist.gov
32
cve-2024-23540
hcl bigfix inventory
path traversal
internal application files
inventory server
static file

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

10.8%

The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "BigFix Inventory",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9.x, 10.x"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

10.8%

Related for CVE-2024-23540