First published: Mon Dec 09 2024(Updated: )
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Digi ConnectPort LTS 8/16/32 | <1.4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50625 has been classified as a medium severity vulnerability due to its potential for arbitrary file uploads and privilege escalation.
To fix CVE-2024-50625, update the Digi ConnectPort LTS to version 1.4.12 or later.
CVE-2024-50625 can allow an attacker to manipulate file paths through malicious POST requests, leading to possible unauthorized access and privilege escalation.
Yes, CVE-2024-50625 affects Digi ConnectPort LTS versions prior to 1.4.12.
CVE-2024-50625 can enable arbitrary file uploads, which may lead to code execution and privilege escalation on the affected system.