CVE-2024-41792

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Apr 8, 2025
CWE ID 22

Summary

CVE-2024-41792 is a newly discovered vulnerability affecting all versions of the SENTRON 7KT PAC1260 Data Manager's web interface. This issue involves a path traversal flaw, which enables unauthenticated attackers to gain root access to arbitrary files on the device. By manipulating the file path requests, an attacker can bypass access controls, potentially leading to data theft or system compromise. This vulnerability poses a significant risk to organizations using the affected device and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share