Back to overview

CVE-2024-57968

CRITICAL KEV CISA Exploitation: ACTIVE
9.9
CVSS 3.1
Description
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

Metadata

CVE ID
CVE-2024-57968
State
PUBLISHED
Assigner
mitre
Reserved
2025-02-03 00:00 UTC
Published
2025-02-03 00:00 UTC
Last updated
2025-10-21 22:55 UTC
Primary CWE
CWE-434
CWE-434 Unrestricted Upload of File with Dangerous Type
Vendor / Product
Advantive / VeraCore
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
no
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Advantive VeraCore Unrestricted File Upload Vulnerability
Vendor
Advantive
Product
VeraCore
Added to KEV
2025-03-10
Due date
2025-03-31
Ransomware
Not known
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
Affected products (1)
VendorProductPlatformVersions
Advantive VeraCore 0 < 2024.4.2.1
Weakness (CWE)
CWESourceDescription
CWE-434 cna CWE-434 Unrestricted Upload of File with Dangerous Type
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview