S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 15, 2024

CVE-2024-6188 Scanner

CVE-2024-6188 scanner - Arbitrary File Disclosure vulnerability in TrakSYS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6188
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269159. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
TrackSYSby Parsec Automation
11.x.x
tracksysby parsec_automation
11.x.x
Updated Aug 22, 2026View on NVD →
Detail

TrakSYS is a manufacturing operations management software used by industries to monitor and control production processes. It is widely adopted by manufacturers for improving efficiency, reducing downtime, and ensuring product quality. The software integrates various manufacturing processes and provides real-time data analytics. It is utilized by plant managers, engineers, and IT professionals to streamline operations. TrakSYS is essential for companies aiming to achieve operational excellence and agility in their manufacturing workflows.

The Arbitrary File Disclosure vulnerability in TrakSYS allows attackers to remotely access and export the source code of specific pages without authentication. This vulnerability is found in the /TS/export/pagedefinition endpoint and is triggered by manipulating the ID parameter. Exploiting this vulnerability can lead to significant information leakage. Public disclosure of the exploit increases the risk of it being used by malicious actors.

The vulnerability resides in the /TS/export/pagedefinition endpoint of TrakSYS. By manipulating the ID parameter, attackers can send crafted requests to export sensitive page source code. The issue is caused by insufficient validation and access control on the ID parameter, allowing unauthorized users to access restricted files. When the crafted request is processed, the server responds with the source code of the page, including sensitive information. This flaw can be exploited without any authentication, making it a critical security risk.

Exploitation of this vulnerability can result in significant information leakage, allowing attackers to gain insights into the internal workings of the TrakSYS application. Attackers can access sensitive data, including configuration details, which may facilitate further attacks. Unauthorized access to source code can lead to the discovery of additional vulnerabilities. The overall security posture of the affected organization could be severely compromised.

Joining the S4E platform gives you access to comprehensive vulnerability scanning and detailed reporting to safeguard your digital assets. Our tools help you identify and mitigate security risks proactively, ensuring robust protection against cyber threats. Stay informed with real-time updates and expert insights tailored to your security needs. Leverage our extensive database of vulnerabilities to keep your systems secure. Enhance your cybersecurity posture with our user-friendly and powerful security solutions.

References:

Solution Advice
  • Implement proper access controls and validation mechanisms for the ID parameter in the /TS/export/pagedefinition endpoint.
  • Regularly update and patch the TrakSYS software to fix known vulnerabilities.
  • Monitor and log access to sensitive endpoints to detect and respond to unauthorized access attempts.
  • Conduct regular security audits and vulnerability assessments to identify and mitigate potential risks.
  • Educate and train staff on secure coding practices and the importance of access controls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.