CVE-2024-10379
Esafenet
CVE-2024-10379 allows for path traversal in ESAFENET CDG 5, enabling unauthorized file access. Specifically, the actionViewDecyptFile function in DecryptApplicationService.java is vulnerable to manipulation via the 'decryptFileId' argument, potentially exposing sensitive files. Despite a CVSS score of 7.5, SOCRadar's Vulnerability Risk Score (SVRS) is 68, indicating a moderate risk but not critical urgency. Successful exploitation could allow attackers to read arbitrary files on the system. The vulnerability has been publicly disclosed, increasing the likelihood of exploitation. Given that the vendor has not responded to the disclosure, organizations using ESAFENET CDG 5 should implement mitigation measures promptly.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.