PT-2024-33523 · Unknown · Themecenter

Natalie Silvanovich

·

Published

2024-12-03

·

Updated

2024-12-03

·

CVE-2024-49411

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ThemeCenter versions prior to SMR Dec-2024 Release 1
Description The issue allows physical attackers to copy apk files to an arbitrary path with ThemeCenter privilege. This is due to a path traversal vulnerability in ThemeCenter.
Recommendations For versions prior to SMR Dec-2024 Release 1, update to SMR Dec-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ThemeCenter privilege to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-49411

Affected Products

Themecenter