CVE-2024-11481

HIGH

Trellix ESM 11.6.10 - Unauthenticated Path Traversal & API Forwarding via Snowservice

Title source: llm
STIX 2.1

Description

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
trellix/enterprise_security_manager 11.6.10
Published Nov 29, 2024
Tracked Since Feb 18, 2026