PT-2024-4083 · 12D Solutions · 12D Synergy File Replication Server+1

James Cuneo

·

Published

2024-02-18

·

Updated

2025-04-02

·

CVE-2024-24722

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions 12d Synergy Server versions prior to 4.3.10.192 12d Synergy Server versions prior to 5.1.5.221 12d Synergy Server versions prior to 5.1.6.235 12d Synergy File Replication Server versions prior to 4.3.10.192 12d Synergy File Replication Server versions prior to 5.1.5.221 12d Synergy File Replication Server versions prior to 5.1.6.235
Description The issue is related to an unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components. This vulnerability may allow an attacker to gain elevated privileges via the service path.
Recommendations For 12d Synergy Server versions prior to 4.3.10.192, update to version 4.3.10.192 or later. For 12d Synergy Server versions prior to 5.1.5.221, update to version 5.1.5.221 or later. For 12d Synergy Server versions prior to 5.1.6.235, update to version 5.1.6.235 or later. For 12d Synergy File Replication Server versions prior to 4.3.10.192, update to version 4.3.10.192 or later. For 12d Synergy File Replication Server versions prior to 5.1.5.221, update to version 5.1.5.221 or later. For 12d Synergy File Replication Server versions prior to 5.1.6.235, update to version 5.1.6.235 or later.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-04532
CVE-2024-24722

Affected Products

12D Synergy File Replication Server
12D Synergy Server