CVE-2024-52378
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 22
Summary
CVE-2024-52378 is a newly disclosed vulnerability affecting Labs64 DigiPass, a software solution for two-factor authentication. This issue involves an improper limitation of a pathname, leading to an Absolute Path Traversal vulnerability. Hackers can exploit this flaw to navigate outside of the intended directory structure, potentially accessing sensitive information or even executing malicious code. The vulnerability affects DigiPass versions from n/a through 0.3.0, underscoring the importance of prompt patching to maintain cybersecurity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share