{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-47253","assignerOrgId":"f2daf9a0-02c2-4b83-a01d-63b3b304b807","state":"PUBLISHED","assignerShortName":"Axis","dateReserved":"2024-09-23T16:37:50.255Z","datePublished":"2024-11-05T09:08:56.300Z","dateUpdated":"2026-01-09T13:31:37.563Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"2N Access Commander","vendor":"2N","versions":[{"status":"affected","version":"<=3.1.1.2"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles."}],"value":"In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f2daf9a0-02c2-4b83-a01d-63b3b304b807","shortName":"Axis","dateUpdated":"2026-01-09T13:31:37.563Z"},"references":[{"url":"https://www.2n.com/en-GB/download/Access-Commander-Security-Advisory-2024-11"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"affected":[{"vendor":"2n","product":"access_commander","cpes":["cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","lessThanOrEqual":"3.1.1.2","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-11-05T14:50:29.094999Z","id":"CVE-2024-47253","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-05T14:54:38.884Z"}}]},"dataVersion":"5.2"}