A AegiFlow
HIGHCVSS 7.5KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2024-57727

CVE-2024-57727 updated by NVD

Published
2025-02-13
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.