Record summary

CVE-2024-8752 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 7, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheck2.15.19affected

Default status: unknown

CVE List2.15.19affected

Proofs of concept

1

Repository PoCs

GitHubD3anSPGDMS/CVE-2024-8752Repository PoCby D3anSPGDMSStars: 0Not analyzed2 files

169 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWebIQ 2.15.9 - Directory TraversalCVSS 7.5

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Impact

Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Windows system, potentially exposing sensitive configuration files, credentials, database files, and system information.

Remediation

Update WebIQ to a version later than 2.15.9 to address the directory traversal vulnerability.

Authorss4e-io
Template tagscvecve2024webiqlfivkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: title:"WebIQ"

Source: ProjectDiscovery

References

2