All CVEs View on NVD
CVE-2024-57727
HIGH7.5
CISA KEV
Published 2025-01-15 · Updated 2026-08-04 · Source cve@mitre.org
Description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-22CWE-22
CISA Known-Exploited Vulnerability
Product: SimpleHelp — SimpleHelp
Name: SimpleHelp Path Traversal Vulnerability
Date added: 2025-02-13 · Due: 2025-03-06
USED IN RANSOMWARE
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
References
- https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier
- https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57727

