CVE-2024-57727
KEV
🔴 Łataj teraz
Wielokrotne luki w SimpleHelp umożliwiają zdalnym atakującym pobieranie plików konfiguracyjnych.
CVSS
7.5
EPSS
95.2%
Exploit
weaponized
Vendor
simple-help
Opis źródłowy (NVD)
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 95.2% |
| Opublikowano (NVD) | 2025-01-15 23:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:31 UTC |
Referencje
- https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier (cve@mitre.org) [Release Notes]
- https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ (cve@mitre.org) [Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57727 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]