peter bassill · operator
$ cve CVE-2024-57727 JSON

CVE-2024-57727 KEV

7.5
HIGH · CVSS 3.1 · EPSS 96.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-06.

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS96.58% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2025-03-06
Public exploitnone known
Published2025-01-15
Last modified2026-08-04

CISA KEV

NameSimpleHelp Path Traversal Vulnerability
Added2025-02-13
Due2025-03-06
Vendor / productSimpleHelp / SimpleHelp
Ransomware useknown

Affected (1)

VendorProduct
simple-helpsimplehelp

References

→ the Explorer  ·  watch your stack  ·  NVD