CVE-2024-52885
MEDIUMDescription
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
Is your site exposed to CVE-2024-52885?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| checkpoint | mobile_access |
| checkpoint | remote_access_vpn |
| checkpoint | gaia_os |
| checkpoint | gaia_os |
| checkpoint | gaia_os |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-52885? +
How severe is CVE-2024-52885? +
What products are affected by CVE-2024-52885? +
How do I check if I'm vulnerable to CVE-2024-52885? +
Related Vulnerabilities
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for …
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not …
Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. …
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path …