Directory Traversal Vulnerability in Allegra Software by Tenable
CVE-2024-5581

7.2HIGH

Key Information:

Vendor

Allegra

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-5581?

The Allegra software has a directory traversal vulnerability in its unzipFile method, which allows remote attackers to execute arbitrary code on the system. This issue arises from insufficient validation of user-supplied file paths before they are used in file operations. Consequently, attackers can exploit this vulnerability to run code with the permissions of the LOCAL SERVICE account. Authentication is necessary for exploitation, emphasizing the need for users to secure their installation against potential threats.

Affected Version(s)

Allegra 7.5.1.9

References

EPSS Score

12% chance of being exploited in the next 30 days.

CVSS V3.0

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.