CVE-2024-49359

HIGH

ZimaOS < 1.2.5 - Authenticated Directory Traversal via File API Endpoint

Title source: llm
STIX 2.1

Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users to list the contents of any directory on the server. By manipulating the path parameter, attackers can access sensitive system directories such as `/etc`, potentially exposing critical configuration files and increasing the risk of further attacks. As of time of publication, no known patched versions are available.

References (2)

Core 2
Core References
Exploit x_refsource_misc
https://youtu.be/IuaEH09ot9s

Scores

CVSS v3 7.5
EPSS 0.0095
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-552 CWE-22
Status published
Products (1)
zimaspace/zimaos < 1.2.5
Published Oct 24, 2024
Tracked Since Feb 18, 2026