Lucene search

K
cveDIVDCVE-2024-27120
HistoryAug 14, 2024 - 8:15 p.m.

CVE-2024-27120

2024-08-1420:15:11
CWE-200
CWE-22
DIVD
web.nvd.nist.gov
31
cve-2024-27120
comfortkey
celsius benelux
unauthenticated attacker
sensitive information
version 24.1.2

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:H/VI:N/SI:N/VA:N/SA:N/S:P/AU:Y/U:Red/R:U/V:C/RE:M

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

39.1%

A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.

Affected configurations

Nvd
Node
celsiusbeneluxcomfortkeyRange<24.1.2
VendorProductVersionCPE
celsiusbeneluxcomfortkey*cpe:2.3:a:celsiusbenelux:comfortkey:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ComfortKey",
    "vendor": "Celsius Benelux",
    "versions": [
      {
        "status": "affected",
        "version": "before 24.1.2"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS4

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:H/VI:N/SI:N/VA:N/SA:N/S:P/AU:Y/U:Red/R:U/V:C/RE:M

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

39.1%

Related for CVE-2024-27120