CVE-2024-37403
Estado: ModificadaMedia (5.5)—
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
- CWE-24
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-37403",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-37403",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-07T13:23:46.024442Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.3
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "Ivanti",
"product": "Docs@Work",
"versions": [
{
"status": "affected",
"version": "2.26.0",
"lessThan": "2.26.0",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-08-07T04:17:18.653",
"references": [
{
"url": "https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android",
"tags": [
"Vendor Advisory"
],
"source": "support@hackerone.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-24"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root."
},
{
"lang": "es",
"value": "Ivanti Docs@Work para Android, versiones anteriores a 2.26.0, se ve afectada por la vulnerabilidad 'Dirty Stream'. La aplicación no puede desinfectar adecuadamente los nombres de los archivos, lo que genera una vulnerabilidad relacionada con el path traversal. Esto potencialmente permite que otras aplicaciones maliciosas en el dispositivo lean información confidencial almacenada en la raíz de la aplicación."
}
],
"lastModified": "2026-06-17T07:38:18.210",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ivanti:docs\\@work:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "FAC4D166-510F-4481-8A1D-77887E56908E",
"versionEndExcluding": "2.26.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}