CVE-2024-4230

HIGH

Edgecross Basic Software <1.00 - Path Traversal

Title source: llm
STIX 2.1

Description

External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-73
Status published
Products (2)
Edgecross Consortium/Edgecross Basic Software for Developers versions 1.00 and later
Edgecross Consortium/Edgecross Basic Software for Windows versions 1.00 and later
Published Dec 19, 2024
Tracked Since Feb 18, 2026