CVE-2024-57968 KEV
9.9
CRITICAL · CVSS 3.1 · EPSS 32.3% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2025-03-31.
Description
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 32.28% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | yes — remediate by 2025-03-31 |
| Public exploit | none known |
| Published | 2025-02-03 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Advantive VeraCore Unrestricted File Upload Vulnerability |
|---|---|
| Added | 2025-03-10 |
| Due | 2025-03-31 |
| Vendor / product | Advantive / VeraCore |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| advantive | veracore |
References
- https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1
- https://intezer.com/blog/research/xe-group-exploiting-zero-days/
- https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968
→ the Explorer · watch your stack · NVD