CVE-2024-11136: Arbitrary file removal via path traversal in TCL Camera
Published Nov 14, 2024
·Updated
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from user’s external storage.
Affected Software
1 affected component
Tcl Camera
Event History
Nov 14, 2024
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11136?
CVE-2024-11136 is classified as a high severity vulnerability due to its potential for data loss and unauthorized access to files.
2
How do I fix CVE-2024-11136?
To fix CVE-2024-11136, ensure that application input validation is properly implemented to sanitize URI paths.
3
What types of devices are affected by CVE-2024-11136?
CVE-2024-11136 specifically affects devices using the default TCL Camera application.
4
What could an attacker achieve through CVE-2024-11136?
An attacker could exploit CVE-2024-11136 to delete arbitrary files from a user's external storage.
5
Is the TCL Camera application the only application affected by CVE-2024-11136?
Yes, CVE-2024-11136 is primarily associated with the TCL Camera application and its associated content provider.