PT-2024-38449 · Trellix · Trellix Fx+5

Published

2024-08-27

·

Updated

2025-07-13

·

CVE-2024-7608

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Trellix NX, EX, FX, AX, IVX, and CMS (affected versions not specified)
Description An authenticated user can access restricted files from Trellix products using path traversal for the URL of network anomaly download artifact. This issue allows the download of sensitive files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-7608

Affected Products

Trellix Ax
Trellix Cms
Trellix Ex
Trellix Fx
Trellix Ivx
Trellix Nx