# CVE-2024-6049

## Summary

- **CVE ID:** CVE-2024-6049
- **Severity:** UNKNOWN
- **CVSS Score:** 2.73
- **CWE:** CWE-32
- **Published:** Oct 24, 2024
- **Last Modified:** Mar 13, 2026

## Description

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

## Affected Products

- Lawo AG — vsm LTC Time Sync (vTimeSync) (4.5.6.0)

## References

- [CNA](https://r.sec-consult.com/lawo)
- [CNA](https://lawo.com/lawo-downloads/)
- [CVE](http://seclists.org/fulldisclosure/2024/Oct/7)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.23%
- **EPSS Percentile:** 90.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._