Back

CRITICAL KEV Used in ransomware campaigns

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests

Published Jan 15, 2025 ·Due Mar 6, 2025

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 15, 2025
Updated Aug 4, 2026
Reserved Jan 9, 2025
CISA Vulnrichment
Updated Feb 14, 2025
NVD
Status Analyzed
Modified Aug 4, 2026
Red Hat
Severity n/a
Public date n/a