cve-2024-57727
CRITICAL CVSS 9.1 cisa_known_exploited
Description
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
Timeline
- Published
- 2025-02-13
- Last Modified
- 2025-02-13
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.1,
"datePublished": "2025-02-13",
"dateUpdated": "2025-02-13",
"description": "SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.",
"dueDate": "2025-03-06",
"id": "CVE-2024-57727",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Known",
"notes": "https://simple-help.com/kb---security-vulnerabilities-01-2025 ; Additional CISA Mitigation Instructions: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a ; https://nvd.nist.gov/vuln/detail/CVE-2024-57727",
"product": "SimpleHelp",
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "SimpleHelp Path Traversal Vulnerability",
"vendor": "SimpleHelp "
}
Enrichment data
Aggregated bundle (all enrichments)