CVE-2024-23540
Last modified
CVE-2024-23540 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file. . EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-23540?
How severe is CVE-2024-23540?
How do I fix CVE-2024-23540?
Are you affected by CVE-2024-23540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
