PT-2024-32092 · Enms · Enms

Published

2024-09-20

·

Updated

2024-09-26

·

CVE-2024-46647

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions eNMS versions 4.4.0 through 4.7.1
Description The issue is related to a Directory Traversal vulnerability. This vulnerability can be exploited through the upload files feature, allowing unauthorized access to sensitive files and directories.
Recommendations For eNMS versions 4.4.0 through 4.7.1, consider disabling the upload files feature until a patch is available to prevent potential exploitation. Restrict access to sensitive files and directories to minimize the risk of unauthorized access.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-46647

Affected Products

Enms