CVE-2024-47253

In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles.
Configurations

Configuration 1 (hide)

cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:*

History

07 Nov 2024, 12:15

Type Values Removed Values Added
References
  • {'url': 'https://www.2n.com/en-GB/about-2n/cybersecurity/', 'tags': ['Product'], 'source': 'product-security@axis.com'}
  • () https://www.2n.com/en-GB/download/Access-Commander-Security-Advisory-2024-11 -

06 Nov 2024, 22:23

Type Values Removed Values Added
First Time 2n
2n access Commander
CPE cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:*
References () https://www.2n.com/en-GB/about-2n/cybersecurity/ - () https://www.2n.com/en-GB/about-2n/cybersecurity/ - Product

05 Nov 2024, 12:15

Type Values Removed Values Added
Summary
  • (es) En las versiones 3.1.1.2 y anteriores de 2N Access Commander, una vulnerabilidad de path traversal podría permitir a un atacante escribir archivos en el sistema de archivos para lograr la ejecución remota de código arbitrario.
Summary (en) In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker to write files on the filesystem to achieve arbitrary remote code execution. (en) In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles.

05 Nov 2024, 10:20

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-05 10:20

Updated : 2024-11-07 12:15


NVD link : CVE-2024-47253

Mitre link : CVE-2024-47253

CVE.ORG link : CVE-2024-47253


JSON object : View

Products Affected

2n

  • access_commander
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')