PT-2024-4579 · Unknown · Sinec Traffic Analyzer

Published

2024-06-11

·

Updated

2024-08-06

·

CVE-2024-35209

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: SINEC Traffic Analyzer versions prior to V1.2
Description: A vulnerability has been identified in the web server of SINEC Traffic Analyzer, which allows HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files. The issue is related to the use of dangerous HTTP methods, potentially enabling a remote attacker to access and modify arbitrary files.
Recommendations: For versions prior to V1.2, consider restricting access to the affected web server or disabling the use of HTTP methods like PUT and Delete as a temporary workaround until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-05085
CVE-2024-35209

Affected Products

Sinec Traffic Analyzer