CVE-2024-24722 is an unquoted service path vulnerability affecting 12d Synergy Server and File Replication Server components, allowing attackers to gain elevated privileges. With a CVSS score of 9.1 (Critical), this vulnerability can be exploited remotely with low complexity, leading to high impact on confidentiality and integrity. While no public exploits or active exploitation have been observed, and community discussion is minimal, organizations should prioritize patching to versions 4.3.10.192, 5.1.5.221, or 5.1.6.235 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.10.192CPE matchmatch criteria | cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:* | ||
>= 5.1.1.58, < 5.1.5.221CPE matchmatch criteria | cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:* | ||
>= 5.1.6.210, < 5.1.6.235CPE matchmatch criteria | cpe:2.3:a:12dsynergy:12dsynergy:*:*:*:*:*:*:*:* | ||
< 4.3.10.192CPE matchmatch criteria | cpe:2.3:a:12dsynergy:file_replication_server:*:*:*:*:*:*:*:* | ||
>= 5.1.1.58, < 5.1.5.221CPE matchmatch criteria | cpe:2.3:a:12dsynergy:file_replication_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.