← back
CVE-2024-8752

WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability

CVSS 9.3 CRITICALEPSS 11.8%CWE-22
Vexday Risk Score
68High priority
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 11.8%KEV nãoPoC públicaNuclei simMetasploit Patch
Lifecycle
16 Sep 2024Published on NVD
19 Sep 2024Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Smart HMI · WebIQ
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →