CVE-2024-31841

HIGH

Italtel Embrace <1.6.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://www.gruppotim.it/it/footer/red-team.html

Scores

CVSS v3 7.5
EPSS 0.0080
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
italtel/embrace 1.6.4
Published Apr 19, 2024
Tracked Since Feb 18, 2026