VYPR
Medium severity5.4NVD Advisory· Published Jun 24, 2024· Updated Apr 15, 2026

CVE-2024-37825

CVE-2024-37825

Description

An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network to perform a directory traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated directory traversal in EnvisionWare SelfCheck v1.0 allows attackers on the same network to access sensitive files on the underlying host.

Vulnerability

Overview

CVE-2024-37825 is a directory traversal vulnerability in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0. The flaw allows unauthenticated attackers on the same network to traverse directories and access files outside the intended web root, potentially exposing sensitive data stored on the host system. The vulnerability exists in the application server component of the SelfCheck software [1][2].

Attack

Vector and Exploitation

The attack vector is network-based, requiring the attacker to be on the same network as the vulnerable SelfCheck server. No authentication is needed, making it easier for an unauthenticated remote attacker to exploit the issue. The directory traversal enables reading arbitrary files from the server's filesystem by manipulating path sequences in HTTP requests [2].

Impact and

Remediation

Successful exploitation could allow an attacker to read sensitive configuration files, credentials, or other data stored on the underlying host. This could facilitate further targeted attacks to compromise the SelfCheck server or the broader network. EnvisionWare has addressed the issue in the OneStop 3.2.0.27184 Hotfix, released in May 2024. It was not disclosed which prior software versions are affected beyond SelfCheck v1.0 [2].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.