Vulnerability Description
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stonefly | Storage Concentrator | < 8.0.4.26 |
Related Weaknesses (CWE)
References
- https://stonefly.comProduct
- https://stonefly.com/security-advisories/cve-2024-31947/Vendor Advisory
- https://stonefly.comProduct
- https://stonefly.com/security-advisories/cve-2024-31947/Vendor Advisory
FAQ
What is CVE-2024-31947?
CVE-2024-31947 is a vulnerability with a CVSS score of 6.5 (MEDIUM). StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system ...
How severe is CVE-2024-31947?
CVE-2024-31947 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-31947?
Check the references section above for vendor advisories and patch information. Affected products include: Stonefly Storage Concentrator.