CVE-2024-46977

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 31, 2024
CWE ID 22

Summary

CVE-2024-46977 is a recently identified vulnerability in OpenC3 COSMOS, an industrial automation software. Maliciously crafted input can exploit a path traversal flaw present in the LocalMode's open_local_file method, granting authenticated users with suitable permissions the ability to download any .txt files. This issue is particularly concerning since it allows attackers to access sensitive data through the ScreensController#show functionality on the COSMOS web server. The vulnerability is rectified in OpenC3 COSMOS version 5.19.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Bishop Fox Cosmos

Affected Vendors

  • Bishop Fox