Arbitrary File Vulnerability in tbm-client from Chunghwa Telecom
CVE-2024-12644

7.1HIGH

Key Information:

Vendor
CVE Published:
16 December 2024

What is CVE-2024-12644?

CVE-2024-12644 describes a critical arbitrary file vulnerability within the tbm-client application developed by Chunghwa Telecom. This vulnerability arises from the application's inability to enforce CSRF protection on its API endpoints, allowing unauthenticated remote attackers to exploit the APIs. Additionally, the presence of an Absolute Path Traversal flaw permits attackers to manipulate file paths, enabling unauthorized access to arbitrary files on a user's system. This could potentially lead to serious information leakage and excessive consumption of disk space as attackers may exploit the vulnerability to copy large volumes of files. Organizations using tbm-client should take immediate action to assess their risk and implement necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

tbm-client 0.3.15 <= 0.3.20

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.