Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
History

Thu, 13 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Advantive
Advantive veracore
CPEs cpe:2.3:a:advantive:veracore:*:*:*:*:*:*:*:*
Vendors & Products Advantive
Advantive veracore

Mon, 10 Mar 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-03-10'}


Mon, 10 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Feb 2025 18:15:00 +0000


Mon, 03 Feb 2025 19:30:00 +0000

Type Values Removed Values Added
Description Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-02-03T00:00:00.000Z

Updated: 2025-03-14T03:55:50.975Z

Reserved: 2025-02-03T00:00:00.000Z

Link: CVE-2024-57968

cve-icon Vulnrichment

Updated: 2025-02-12T20:41:56.127Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-03T20:15:36.550

Modified: 2025-03-13T14:31:46.370

Link: CVE-2024-57968

cve-icon Redhat

No data.