CVE-2024-52885: Path Traversal
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52885?
CVE-2024-52885 is classified as a high severity vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2024-52885?
To mitigate CVE-2024-52885, ensure that you are using updated software versions of Checkpoint Mobile Access and Remote Access VPN that include patches addressing this vulnerability.
Who is affected by CVE-2024-52885?
CVE-2024-52885 affects authenticated users of Checkpoint Mobile Access Portal's File Share application with access to 'nobody'-accessible directories.
What type of attack is associated with CVE-2024-52885?
CVE-2024-52885 is associated with a directory traversal attack that can expose sensitive file names to malicious users.
What versions are impacted by CVE-2024-52885?
CVE-2024-52885 affects older versions of Checkpoint Mobile Access and Remote Access VPN prior to recommended security updates.