ESAFENET CDG 5 Path Traversal via /DecryptApplicationService
CVE-2024-10379 Published on October 25, 2024

ESAFENET CDG DecryptApplicationService.java actionViewDecyptFile path traversal
A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument decryptFileId with the input ../../../Windows/System32/drivers/etc/hosts leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The affected function has a typo and is missing an R. The vendor was contacted early about this disclosure but did not respond in any way.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Type

Path Traversal: '../filedir'

The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.


Products Associated with CVE-2024-10379

Want to know whenever a new CVE is published for Esafenet Cdg? stack.watch will email you.

 

Affected Versions

ESAFENET CDG: esafenet cdg:

Exploit Probability

EPSS
0.77%
Percentile
73.92%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.