← Back to browse · API

CVE-2024-6127

Severity
CRITICAL
CVSS
9.8
EPSS
0.10263
Risk score
42.79
CISA KEV
No
PoC
No
Published
2024-06-27
Modified
2026-07-14
First seen
2026-08-07
Aliases
EUVD-2024-47274, GHSA-24R9-8WX9-6G9F
Products
BC Security:Empire 0 <5.9.3
Sources
euvd EUVD-2024-47274

Description

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

References