Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48499 | An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal. |
| Link | Providers |
|---|---|
| https://thrive.trellix.com/s/article/000013844 |
|
Wed, 28 Aug 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 28 Aug 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user can download sensitive files from NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact. | An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal. |
Wed, 28 Aug 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user can download sensitive files from Trellix products NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact. | An authenticated user can download sensitive files from NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact. |
Tue, 27 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user can download sensitive files from Trellix products NX, EX, FX, AX, IVX, and CMS using path traversal for the URL of network anomaly download_artifact. | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-28T11:45:52.314Z
Reserved: 2024-08-08T05:27:33.710Z
Link: CVE-2024-7608
Updated: 2024-08-27T15:14:03.313Z
Status : Deferred
Published: 2024-08-27T08:15:05.980
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-7608
No data.
OpenCVE Enrichment
No data.
EUVD