« Volver al listado

CVE-2024-52885

Estado: AnalizadaMedia (5.4)—

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-52885",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-52885",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-06T15:02:46.396665Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@checkpoint.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "checkpoint",
          "product": "Check Point Mobile Access",
          "versions": [
            {
              "status": "affected",
              "version": "Check Point Mobile Access versions R81.10, R81.20, R82"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-08-06T15:15:31.287",
  "references": [
    {
      "url": "https://support.checkpoint.com/results/sk/sk183137",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-35"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway."
    },
    {
      "lang": "es",
      "value": "La aplicación Mobile Access Portal's File Share es vulnerable a un ataque de directory traversal, lo que permite que un usuario final malintencionado y autenticado (autorizado a al menos una aplicación File Share) enumere los nombres de archivos de directorios a los que \"nadie\" puede acceder en el portal de acceso móvil."
    }
  ],
  "lastModified": "2026-06-17T08:07:48.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:mobile_access:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "615942BD-BD17-41D7-8581-F5B7C7937BD5"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:remote_access_vpn:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CE7D305-2FF3-4003-8127-C2DB68E06AC8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.10:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "55864700-51C8-4540-B4B2-05CE4C7FC245"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.20:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3BE80E1E-02E1-44E3-B309-3079F0F5A89C"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r82:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6443AE50-1CB5-4D00-8C8D-97DB966687DD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}