« Volver al listado

CVE-2024-24722

Estado: AnalizadaCrítica (9.1)—

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-24722",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-24722",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-25T15:51:52.455219Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:12dsynergy:12d_synergy_server:*:*:*:*:*:*:*:*"
          ],
          "vendor": "12dsynergy",
          "product": "12d_synergy_server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.3.10.192",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.1.5.221",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.1.6.235",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:12dsynergy:12d_synergy_file_replication_server:*:*:*:*:*:*:*:*"
          ],
          "vendor": "12dsynergy",
          "product": "12d_synergy_file_replication_server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.3.10.192",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.1.5.221",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.1.6.235",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-19T06:15:07.890",
  "references": [
    {
      "url": "https://files.12dsynergy.com/downloads/download.aspx",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://help.12dsynergy.com/v1/docs/cve-2024-24722",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.12dsynergy.com/security-statement/",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://files.12dsynergy.com/downloads/download.aspx",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://help.12dsynergy.com/v1/docs/cve-2024-24722",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.12dsynergy.com/security-statement/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta de servicio sin comillas en los componentes de 12d Synergy Server y File Replication Server puede permitir que un atacante obtenga privilegios elevados a través de la ruta de servicio ejecutable de 12d Synergy Server y/o 12d Synergy File Replication Server. Esto se solucionó en 4.3.10.192, 5.1.5.221 y 5.1.6.235."
    }
  ],
  "lastModified": "2026-06-17T07:14:45.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8871AAB-DE20-4C24-A8E7-D99F0269772F",
              "versionEndExcluding": "4.3.10.192"
            },
            {
              "criteria": "cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E33EBB03-AFF8-4E28-B6E7-B9F1F319DB65",
              "versionEndExcluding": "5.1.5.221",
              "versionStartIncluding": "5.1.1.58"
            },
            {
              "criteria": "cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FAA3310-1CE6-4589-8747-B8B183E9139F",
              "versionEndExcluding": "5.1.6.235",
              "versionStartIncluding": "5.1.6.210"
            },
            {
              "criteria": "cpe:2.3:a:12dsynergy:file_replication_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BF4A547-6B81-4403-8FA8-18D616005B3F",
              "versionEndExcluding": "4.3.10.192"
            },
            {
              "criteria": "cpe:2.3:a:12dsynergy:file_replication_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE728FBD-5404-4863-B0D9-A43AA9C5C340",
              "versionEndExcluding": "5.1.5.221",
              "versionStartIncluding": "5.1.1.58"
            },
            {
              "criteria": "cpe:2.3:a:12dsynergy:file_replication_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D07AB6E6-65ED-4A32-9146-484407794EC3",
              "versionEndExcluding": "5.1.6.235",
              "versionStartIncluding": "5.1.6.210"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}