CVE-2024-27120: Celsiusbenelux Comfortkey
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacker may retrieve sensitive information about the underlying system. The vulnerability has been remediated in version 24.1.2.
Affected products
- Celsiusbenelux Comfortkey: before 24.1.2 (fixed in 24.1.2)
Published 2024-08-14. Last modified 2026-06-17.