← Volver a CVEs
CVE-2024-57968
CRITICALCISA KEV9.9
Descripcion
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Detalles CVE
Puntuacion CVSS v3.19.9
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado2/3/2025
Ultima modificacion11/4/2025
Fuentekev
Avistamientos honeypot0
CISA KEV
VendedorAdvantive
ProductoVeraCore
Nombre vulnerabilidadAdvantive VeraCore Unrestricted File Upload Vulnerability
Fecha inclusion KEV2025-03-10
Fecha limite remediacion2025-03-31
Uso en ransomwareUnknown
Productos afectados
advantive:veracore
Debilidades (CWE)
CWE-434CWE-434
Referencias
https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/(cve@mitre.org)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.