CVE-2024-37403 is a path traversal vulnerability, dubbed 'Dirty Stream,' affecting Ivanti Docs@Work for Android versions prior to 2.26.0. The flaw stems from improper sanitization of filenames, allowing malicious applications on the same device to read sensitive data stored within the Docs@Work app's root directory. With a CVSS score of 5.5 (Medium), it requires user interaction and local access, but can lead to high confidentiality impact. There is no evidence of active exploitation, nor are public exploit codes available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.26.0CPE matchmatch criteria | cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:* | ||
>= 2.26.0, < 2.26.0CPE match | cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.