CVE-2024-57968: Advantive VeraCore Unrestricted File Upload Vulnerability
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Other sources
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantive VeraCoreto a version that resolves this vulnerability.Fixed in 2024.4.2.1 - Remove
Remove
Advantive VeraCorefrom your environment.Discontinue use of the product if mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions to prevent unrestricted file uploads via upload.aspx.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services for additional mitigations and protections.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-57968?
CVE-2024-57968 is considered a medium severity vulnerability due to its potential for file upload exploitation.
How do I fix CVE-2024-57968?
To fix CVE-2024-57968, upgrade Advantive VeraCore to version 2024.4.2.1 or later.
Who is affected by CVE-2024-57968?
Remote authenticated users of Advantive VeraCore versions prior to 2024.4.2.1 are affected by CVE-2024-57968.
What type of vulnerability is CVE-2024-57968?
CVE-2024-57968 is a directory traversal vulnerability that allows unintended file uploads.
What are the consequences of CVE-2024-57968?
The consequences of CVE-2024-57968 include unauthorized file access and potential exposure of sensitive data.