CVE-2024-6580

MEDIUM

IPWorks SSH <24.0.8945 - Path Traversal

Title source: llm
STIX 2.1

Description

The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1390 CWE-347
Status published
Products (2)
nsoftware/ipworks_ssh 22.0.8945
nsoftware/ipworks_ssh 24.0.8945
Published Jul 08, 2024
Tracked Since Feb 18, 2026