Lucene search

K
cveMitreCVE-2024-31947
HistoryJul 12, 2024 - 11:15 p.m.

CVE-2024-31947

2024-07-1223:15:10
CWE-22
mitre
web.nvd.nist.gov
23
stonefly
directory traversal
authenticated users
crafted path parameter
online help
sensitive system information

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

19.8%

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.

Affected configurations

Nvd
Node
stoneflystorage_concentratorRange<8.0.4.26
VendorProductVersionCPE
stoneflystorage_concentrator*cpe:2.3:a:stonefly:storage_concentrator:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

19.8%

Related for CVE-2024-31947