CVE-2024-27180
An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.
- CVSS 3.1
- 6.7 MEDIUM
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-276
- NVD status
- Deferred
- Published
- 2024-06-14
- Attack patterns
- CAPEC-29
- Entry point
- /./../../../../../home/SYSROM_SRC/build/common/bin/networkservice/ldapserver nested
- Path
- /contentwebserver/upload
Fix
This issue is fixed in the version released on June 14, 2024 and all later versions.
CVE-2024-27180 at NVD
1 known exploit for CVE-2024-27180
Proof-of-concept code and exploit modules indexed by Sploitus