CVE-2020-24113

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Aug 22, 2023
Updated: Aug 28, 2023
CWE ID 22

Summary

CVE-2020-24113 is a Directory Traversal vulnerability affecting the Contacts File Upload Interface in Yealink W60B version 77.83.0.85. Attackers can exploit this vulnerability to gain unauthorized access to sensitive information and trigger a Denial of Service (DoS) condition. By manipulating the file upload functionality, they can traverse beyond intended directories and access restricted data. This issue poses a significant security risk and requires immediate attention from Yealink to release a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share