Description

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

INFO

Published Date :

2024-12-09T00:00:00.000Z

Last Modified :

2024-12-11T20:52:29.818Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-50625 vulnerability.

Vendors Products
Digi
  • Connectport Lts 16
  • Connectport Lts 16 Mei
  • Connectport Lts 16 Mei 2ac
  • Connectport Lts 32
  • Connectport Lts 32 Mei
  • Connectport Lts 8 Mei
  • Connectport Lts Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact