CVE Vulnerabilities

CVE-2024-39776

Storage of File with Sensitive Data Under Web Root

Published: Aug 22, 2024 | Modified: Sep 04, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Weakness

The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.

Affected Software

Name Vendor Start Version End Version
Outpost_uploader_utility Avtecinc * 5.0.0 (excluding)

Potential Mitigations

References