CVE-2024-38449

HIGH

KasmVNC <1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 - Path Trav...

Title source: llm
STIX 2.1

Description

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.

Scores

CVSS v3 7.7
EPSS 0.0096
EPSS Percentile 57.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Published Jun 17, 2024
Tracked Since Feb 18, 2026