CVE-2024-6127: BC Security Empire Path Traversal RCE
Published Jun 27, 2024
·Updated
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.
Affected Software
1 affected component
BC Security Empire<5.9.3
Event History
Jun 27, 2024
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Nov 1, 56586
Event
via FIRST·01:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-6127?
CVE-2024-6127 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2024-6127?
To fix CVE-2024-6127, upgrade BC Security Empire to version 5.9.4 or later.
3
Who is affected by CVE-2024-6127?
CVE-2024-6127 affects all versions of BC Security Empire prior to 5.9.3.
4
What type of vulnerability is CVE-2024-6127?
CVE-2024-6127 is a path traversal vulnerability that can lead to remote code execution.
5
Can CVE-2024-6127 be exploited by authenticated users?
No, CVE-2024-6127 can be exploited by remote, unauthenticated attackers.