CVE-2024-27311 Vulnerability Details

  /     /     /  

CVE-2024-27311 Metadata Quick Info

CVE Published: 17/07/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: ManageEngine | Vendor: ManageEngine | Product: DDI Central
Status : PUBLISHED

CVE-2024-27311 Description

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

Metrics

CVSS Version: 3.1 | Base Score: 5.5 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-434
CWE Name: CWE-434 Unrestricted Upload of File with Dangerous Type
Source: ManageEngine

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-650
CAPEC Description: CAPEC-650 Upload a Web Shell to a Web Server


Source: NVD (National Vulnerability Database).