CVE-2024-6049
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.
Scoring
- CVSS base score
- 2.73
- EPSS probability
- 4.23%
- CWE
- CWE-32
- Published
- 2024-10-24
- Last modified
- 2026-03-13
Affected products
- Lawo AG vsm LTC Time Sync (vTimeSync)
Weakness type
Related vulnerabilities
- CVE-2024-41784 — IBM Sterling Secure Proxy directory traversal