S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Nov 6, 2024

CVE-2024-6049 Scanner

CVE-2024-6049 Scanner - Path Traversal vulnerability in Lawo AG vsm LTC Time Sync (vTimeSync)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6049
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
vsm LTC Time Sync (vTimeSync)by Lawo AG
4.5.6.0
vsm_ltc_timesyncby lawo
AFFECTED< 4.5.6.0SAFE ✓≥ 4.5.6.0
Updated Sep 10, 2026View on NVD →
Detail

The vTimeSync software contains a path traversal vulnerability that allows unauthorized remote attackers to access restricted files on the operating system. This vulnerability is triggered by a specially crafted HTTP request that bypasses path restrictions. The attacker can leverage this flaw to retrieve sensitive files with specific extensions, such as .exe or .txt. This path traversal flaw may expose system files, potentially leading to information disclosure or further exploitation.

The vulnerability lies within the HTTP request handler, where insufficient validation allows the use of “...” (triple-dot) in URL paths to bypass directory restrictions. An attacker could craft a request containing multiple instances of “...” to reach sensitive directories. By targeting specific file extensions, the exploit gains access only to files that match the permissible extensions, such as configuration files or logs. This restriction, while limiting the scope, still allows the unauthorized exposure of important system information. The flaw can be exploited remotely without authentication, making it accessible to external threats.

If exploited, this vulnerability can expose sensitive data stored on the operating system, leading to potential data breaches. Attackers could leverage the exposed information to understand system configuration, gain insights into network settings, or extract files critical to the media production process. Such access might allow attackers to plan further intrusions, compromise other parts of the infrastructure, or manipulate time synchronization in media broadcasts, potentially causing delays or inaccuracies in content delivery.

By joining the S4E platform, you gain continuous, real-time insights into vulnerabilities like those affecting Lawo vTimeSync. Our tools empower you to detect and address security flaws efficiently, ensuring your systems remain compliant and secure. Enjoy access to advanced scanners, detailed reports, and actionable recommendations that help safeguard your network and media infrastructure. Join SecurityForEveryone to experience proactive, reliable security management and keep your assets protected against the latest vulnerabilities.

References:

Solution Advice
  • Ensure the latest patches for vTimeSync are applied as soon as available.
  • Restrict server access to only trusted users and implement strict firewall rules.
  • Regularly audit and monitor access logs for signs of unusual or suspicious file requests.
  • Set up alerts for unauthorized access attempts targeting critical system files.
  • Use an intrusion detection system (IDS) to detect path traversal attack patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-6049 Scanner - Path Traversal vulnerability in Lawo AG vsm LTC Time Sync (vTimeSync) | S4E