V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-24722
CVE
Critical

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain eleva…

CVSS
9.1
Critical
EPSS
0.01
p44
Published
2024-01-01
Updated
2024-01-01
Description

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.

Tags · CWE
Pre-auth
CWE-428
Affected products
12dsynergy < 4.3.10.19212dsynergy 5.1.1.58–5.1.5.22112dsynergy 5.1.6.210–5.1.6.235File_replication_server < 4.3.10.192File_replication_server 5.1.1.58–5.1.5.221File_replication_server 5.1.6.210–5.1.6.235
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.006 · p44
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
12dsynergy*Tracked
file_replication_server*Tracked
Source databases
CVE
Related vulnerabilities