CVE-2024-27120

A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.
References
Link Resource
https://csirt.divd.nl/CVE-2024-27120 Third Party Advisory
https://csirt.divd.nl/DIVD-2024-00031/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:celsiusbenelux:comfortkey:*:*:*:*:*:*:*:*

History

20 Aug 2024, 19:08

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Se ha encontrado una vulnerabilidad de inclusión de archivos locales en ComfortKey, un producto de Celsius Benelux. Al utilizar esta vulnerabilidad, un atacante no autenticado puede recuperar información confidencial sobre el sistema subyacente. La vulnerabilidad se ha solucionado en la versión 24.1.2.
References () https://csirt.divd.nl/CVE-2024-27120 - () https://csirt.divd.nl/CVE-2024-27120 - Third Party Advisory
References () https://csirt.divd.nl/DIVD-2024-00031/ - () https://csirt.divd.nl/DIVD-2024-00031/ - Third Party Advisory
CPE cpe:2.3:a:celsiusbenelux:comfortkey:*:*:*:*:*:*:*:*
CWE CWE-22
First Time Celsiusbenelux comfortkey
Celsiusbenelux

14 Aug 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 20:15

Updated : 2024-08-20 19:08


NVD link : CVE-2024-27120

Mitre link : CVE-2024-27120

CVE.ORG link : CVE-2024-27120


JSON object : View

Products Affected

celsiusbenelux

  • comfortkey
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor