CVE-2024-57727

KEV
🔴 Łataj teraz

Wielokrotne luki w SimpleHelp umożliwiają zdalnym atakującym pobieranie plików konfiguracyjnych.

CVSS
7.5
EPSS
95.2%
Exploit
weaponized
Vendor
simple-help
Opis źródłowy (NVD)

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

path-traversal Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)95.2%
Opublikowano (NVD)2025-01-15 23:15:09 UTC
Ostatnia modyfikacja (NVD)2026-08-04 05:16:31 UTC
Referencje