Lucene search

K
cvelistHCLCVELIST:CVE-2024-23540
HistoryApr 03, 2024 - 4:32 p.m.

CVE-2024-23540 HCL BigFix Inventory is vulnerable to path traversal

2024-04-0316:32:51
HCL
www.cve.org
2
hcl bigfix inventory
path traversal
vulnerability
attacker
internal files
server security

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.5

Confidence

High

EPSS

0

Percentile

10.8%

The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "BigFix Inventory",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "9.x, 10.x"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

5.5

Confidence

High

EPSS

0

Percentile

10.8%

Related for CVELIST:CVE-2024-23540