CVE-2024-1303

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 12, 2024
CWE ID 22

Summary

CVE-2024-1303 is a vulnerability affecting Badger Meter Monitool versions up to 4.6.3. This issue arises from the software's incorrect restriction of directory paths. An authenticated attacker can exploit this flaw to download any file from the affected device by manipulating the download-file functionality. This vulnerability poses a significant risk, as it grants an attacker unauthorized access to sensitive information stored on the device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share