CVE-2024-46977
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 2, 2024
Updated: Oct 31, 2024
CWE ID 22
Summary
CVE-2024-46977 is a recently identified vulnerability in OpenC3 COSMOS, an industrial automation software. Maliciously crafted input can exploit a path traversal flaw present in the LocalMode's open_local_file method, granting authenticated users with suitable permissions the ability to download any .txt files. This issue is particularly concerning since it allows attackers to access sensitive data through the ScreensController#show functionality on the COSMOS web server. The vulnerability is rectified in OpenC3 COSMOS version 5.19.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Bishop Fox Cosmos
Affected Vendors
- Bishop Fox