A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.
History

Tue, 20 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Celsiusbenelux
Celsiusbenelux comfortkey
Weaknesses CWE-22
CPEs cpe:2.3:a:celsiusbenelux:comfortkey:*:*:*:*:*:*:*:*
Vendors & Products Celsiusbenelux
Celsiusbenelux comfortkey
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 15 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Celsius Benelux
Celsius Benelux comfortkey
CPEs cpe:2.3:a:celsius_benelux:comfortkey:*:*:*:*:*:*:*:*
Vendors & Products Celsius Benelux
Celsius Benelux comfortkey
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 20:15:00 +0000

Type Values Removed Values Added
Description A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.
Title Local File Inclusion in ComfortKey before version 24.1.2
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/S:P/AU:Y/R:U/V:C/RE:M/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published: 2024-08-14T19:56:50.598Z

Updated: 2024-09-11T13:41:16.159Z

Reserved: 2024-02-19T19:21:08.621Z

Link: CVE-2024-27120

cve-icon Vulnrichment

Updated: 2024-08-15T13:27:36.046Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-14T20:15:11.730

Modified: 2024-08-20T19:08:54.490

Link: CVE-2024-27120

cve-icon Redhat

No data.