← Back

CVE-2024-50625

nvd nist
Published: Dec 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

Affected (1)

1 product
Connectport Lts Firmware
Configuration A
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Before 1.4.12
Running on/withPlatform Versions
Digi
Connectport Lts 16
All versions
Digi
Connectport Lts 16 Mei
All versions
Digi
Connectport Lts 16 Mei 2ac
All versions
Digi
Connectport Lts 32
All versions
Digi
Connectport Lts 32 Mei
All versions
Digi
Connectport Lts 8 Mei
All versions

Timeline

No history available yet.