CVE-2024-6049
Unauthenticated Path Traversal
Record summary
CVE-2024-6049 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
vsm LTC Time Sync (vTimeSync)Browse Lawo AG / vsm LTC Time Sync (vTimeSync)Default status: affected | CVE List | 4.5.6.0 | unaffected |
vsm_ltc_timesyncBrowse lawo / vsm_ltc_timesyncDefault status: affected | CVE List | Before 4.5.6.0 | unaffected |
Nuclei templates
1ProjectDiscoveryHIGHLawo AG vsm LTC Time Sync (vTimeSync) - Path TraversalCVSS 7.5
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.
Impact
Unauthenticated attackers can exploit triple dot path traversal to download arbitrary files from the operating system, potentially exposing configuration files and credentials.
Remediation
Update Lawo AG vsm LTC Time Sync (vTimeSync) to the latest version that addresses the path traversal vulnerability.
Source: ProjectDiscovery