CVE-2024-8752 describes a directory traversal vulnerability in the Windows version of WebIQ 2.15.9, allowing remote attackers to read arbitrary files on the affected system. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely without user interaction to achieve high confidentiality impact. While not currently listed in CISA's KEV catalog, exploit templates are available for tools like Nuclei, and its high EPSS score suggests a significant probability of exploitation. Despite the high risk, there is currently no public exploit code on platforms like Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.15.9CPE matchmatch criteria | cpe:2.3:a:smart-hmi:webiq:2.15.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
Sep 12, 2024WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
Sep 12, 2024WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
Sep 12, 2024