8.8

CVE-2024-50627

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to unauthorized system access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DigiConnectport Lts Firmware Version < 1.4.12
   DigiConnectport Lts 16 Version-
   DigiConnectport Lts 16 Mei Version-
   DigiConnectport Lts 16 Mei 2ac Version-
   DigiConnectport Lts 32 Version-
   DigiConnectport Lts 32 Mei Version-
   DigiConnectport Lts 8 Mei Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.36
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.