CVE-2024-57727 Details
Description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
A path traversal vulnerability has been identified in SimpleHelp remote support software versions 5.5.7 and prior. This vulnerability allows unauthenticated remote attackers to download arbitrary files from the SimpleHelp host by sending crafted HTTP requests. The downloaded files may include sensitive server configuration files containing various secrets and hashed user passwords.
Users are advised to upgrade to SimpleHelp version 5.5.8 or later. Instructions for upgrading are available on the SimpleHelp website. For users on version 5.4, a specific patch is available, and for those on version 5.3, a different patch is also accessible. After upgrading, it is recommended to change passwords for the administrator and technician accounts, restrict login IP addresses, and create server event alerts for critical actions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| SimpleHelp Path Traversal Vulnerability | Feb 13, 2025 | Mar 6, 2025 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| simple-help simplehelp | < 5.5.8 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jun 9, 2025 | Modified Analysis | [email protected] |
| Jun 6, 2025 | CVE Modified | CISA-ADP |
| Mar 14, 2025 | Modified Analysis | [email protected] |
| Feb 14, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 16, 2025 | Initial Analysis | [email protected] |
| Jan 15, 2025 | New CVE Received | [email protected] |