File and Directory Exposure in Affected Vendor Product
CVE-2024-41699
7.5HIGH
What is CVE-2024-41699?
A significant vulnerability has been discovered in Leading Vendor Inc.'s Major Product Suite that could allow unauthorized access to sensitive files and directories. This exposure arises when misconfigured security settings allow external parties to circumvent intended access controls, potentially leading to data leakage. Organizations utilizing affected versions may find their sensitive information accessible to malicious actors, increasing the risk of data breaches. It is imperative for users to apply recommended security patches and conduct thorough audits of their configuration settings to mitigate this risk.
Affected Version(s)
Priority All versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gad Abuhatziera, Nimrod Bickels, Itay Cherdman - Sophtix Security LTD
