PT-2024-4579 · Unknown · Sinec Traffic Analyzer
Published
2024-06-11
·
Updated
2024-08-06
·
CVE-2024-35209
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
SINEC Traffic Analyzer versions prior to V1.2
Description:
A vulnerability has been identified in the web server of SINEC Traffic Analyzer, which allows HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files. The issue is related to the use of dangerous HTTP methods, potentially enabling a remote attacker to access and modify arbitrary files.
Recommendations:
For versions prior to V1.2, consider restricting access to the affected web server or disabling the use of HTTP methods like PUT and Delete as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sinec Traffic Analyzer