Junglewise Threat Intelligence

CVE-2024-55401: 4C Strategies Exonaut directory traversal

CVE-2024-55401 · Severity: medium · CVSS 6.5 · Published 2025-08-07

Technologies: 4C Strategies Exonaut.

Executive brief

A security vulnerability has been identified in 4C Strategies Exonaut, a software platform used for crisis management and organizational resilience. This flaw allows unauthorized individuals to access files on the server that should be restricted. Such an exploit could lead to the exposure of sensitive configuration data or internal system files, potentially compromising the integrity of the platform's operations.

Technical details

A directory traversal vulnerability (CWE-22) exists in 4C Strategies Exonaut versions prior to 21.6.2.1-1 and 22.4. The flaw stems from improper limitation of a pathname to a restricted directory, which can be exploited by a remote, unauthenticated attacker via network requests. By using specially crafted input containing 'dot-dot-slash' (../) sequences, an attacker can navigate outside the intended web root to read or potentially modify files on the underlying file system. The vulnerability is resolved in versions 21.6.2.1-1 and 22.4.

Affected products

  • 4C Strategies Exonaut before 21.6.2.1-1, and 22.x before 22.4

Timeline

  • 2025-08-07: disclosed
  • 2025-08-07: advisory

References