Junglewise Threat Intelligence

CVE-2024-12367: Vegagrup Software Vega Master directory indexing vulnerability

CVE-2024-12367 · Severity: high · CVSS 8.6 · Published 2025-09-16

Executive brief

Vegagrup Software Vega Master is susceptible to a vulnerability that allows unauthorized users to view the contents of server directories. This could lead to the exposure of sensitive system files and configuration data, potentially compromising the security and operational integrity of the software. An attacker could use this information to gain deeper access to the system or disrupt business operations.

Technical details

A vulnerability classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere) exists in Vegagrup Software Vega Master. The flaw allows for directory indexing, which enables a remote, unauthenticated attacker to browse the file system structure via the network. By exploiting this, an attacker can identify and access sensitive files that are not intended for public viewing. As of the advisory date, the vendor has not confirmed the completion of a fix, and the vulnerability affects versions from v.1.12.35 through September 2025.

Affected products

  • Vegagrup Software Vega Master v.1.12.35 through 20250916

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory

References