PT-2024-24238 · Italtel · Italtel Embrace

Fabio Romano

+3

·

Published

2024-04-19

·

Updated

2024-07-03

·

CVE-2024-31841

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Italtel Embrace version 1.6.4
Description An issue was discovered where the web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
Recommendations For Italtel Embrace version 1.6.4, ensure proper input sanitization is implemented in the web server to prevent unauthorized file access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-31841

Affected Products

Italtel Embrace