CVE-2024-24722

CRITICAL

12d Synergy <5.1.5.221 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.

Scores

CVSS v3 9.1
EPSS 0.0021
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-428
Status published
Products (2)
12dsynergy/12dsynergy < 4.3.10.192
12dsynergy/file_replication_server < 4.3.10.192
Published Feb 19, 2024
Tracked Since Feb 18, 2026