CVE-2024-12367

HIGH

Vegagrup Software Vega Master <20250916 - Info Disclosure

Title source: llm
STIX 2.1

Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing.This issue affects Vega Master: from v.1.12.35 through 20250916.  NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.

Scores

CVSS v3 8.6
EPSS 0.0006
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
Vegagrup Software/Vega Master v.1.12.35 - 20250916
Published Sep 16, 2025
Tracked Since Feb 18, 2026