First published: Mon Mar 25 2024(Updated: )
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
Credit: product.security@lge.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Assistant | ||
LG LED Assistant | =2.1.65 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-2863 is classified as high due to its potential to allow remote attackers to execute unauthorized file uploads.
To fix CVE-2024-2863, ensure that you apply the latest security updates provided by LG for the LED Assistant software.
CVE-2024-2863 affects users of the LG LED Assistant software that have not implemented the necessary security measures.
CVE-2024-2863 may allow unauthorized file access and potential system compromise, impacting the integrity and confidentiality of user data.
A temporary workaround for CVE-2024-2863 includes restricting access to the file upload feature until a patch is applied.