Cyber Resilience

CVE-2024-11948

Gfi Archiver ≤ 15.7

Published
12 December 2024
Modified
13 December 2024
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.014 70th percentile
Risk Priority 77 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2024-11948 is a critical-severity an unspecified weakness vulnerability in Gfi Archiver. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 30% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer.…

more

The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-2037Same product: Gfi Archiver
CVE-2026-2039Same product: Gfi Archiver
CVE-2026-2038Same product: Gfi Archiver
CVE-2024-11949Same product: Gfi Archiver
CVE-2026-2036Same product: Gfi Archiver
CVE-2024-11947Same product: Gfi Archiver
CVE-2025-2975Same vendor: Gfi
CVE-2025-34491Same vendor: Gfi
CVE-2025-34070Same vendor: Gfi
CVE-2026-23753Same vendor: Gfi

Affected Assets

gfi
archiver
≤ 15.7

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References