AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-5178

MEDIUM · CVSS 4.9 EPSS 33.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-07-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.9. Its EPSS score suggests a 33.6% probability of exploitation in the next 30 days.

CVE
CVE-2024-5178
Severity
MEDIUM
CVSS
4.9
EPSS
33.59%

Original NVD Description

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.