PT-2024-32645 · Scout · Scout

Letm3Through

·

Published

2024-09-30

·

Updated

2024-11-15

·

CVE-2024-47531

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Scout versions prior to 4.89
Description The issue arises from the lack of sanitization in filenames, allowing bypass of intended file extensions. This enables the download of malicious files with any extension. If users unknowingly download and open these files, it may lead to device or data compromise.
Recommendations For versions prior to 4.89, update to version 4.89 to resolve the issue. As a temporary workaround, consider restricting the download of files from the Scout visualizer to minimize the risk of exploitation. Avoid opening files downloaded from the visualizer until the issue is resolved.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2024-47531
GHSA-24XV-Q29V-3H6R

Affected Products

Scout