Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
CISA and the FBI are urging software manufacturers to prevent path traversal defects through secure design, formal testing, and fixes that carry through product releases and updates. For customers, the alert is a prompt to ask vendors for evidence of testing and mitigations, and to use CISA’s Known Exploited Vulnerabilities (KEV) catalog to prioritize known exploited flaws.
What path traversal is—and why CISA is highlighting it
Path traversal is a software weakness in which attacker-controlled pathname input can escape the directory boundary an application is meant to enforce, potentially reaching files or resources outside its permitted location. CISA maps the central weakness to CWE-22; CWE-23 describes a related traversal variant. The defect is not limited to a particular vendor, programming language, or industry.
In its May 2024 Secure by Design Alert, “Eliminating Directory Traversal Vulnerabilities in Software,” CISA and the FBI cited threat-actor campaigns exploiting directory-traversal flaws, including CVE-2024-1708 and CVE-2024-20345. The alert said these vulnerabilities affected users of software in critical-infrastructure sectors, including Healthcare and Public Health. It also reported that 55 directory-traversal vulnerabilities were in CISA’s KEV catalog as of May 2024. That is a dated count, not a current total: catalog membership and vendor remediation status can change.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →What software manufacturers should do
The alert treats path traversal as a design and implementation problem manufacturers can address with safe defaults and controlled path handling—not as a risk customers should have to compensate for on their own. CISA and the FBI recommend formal testing using OWASP’s “Testing Directory Traversal File Include” guidance.
#1 Best Overall
Build controls into the product lifecycle
- Set secure path-handling requirements during design, before product behavior and directory boundaries are fixed.
- Use code review and controlled handling of paths to identify and prevent inputs from escaping the intended location.
- Require formal directory-traversal testing across products and retain evidence that the tests were performed.
- If testing finds missing mitigations, direct developers to implement fixes promptly across current and future products.
- Keep the protections in place through release and update processes rather than treating them as a one-time development task.
CISA and the FBI summarize the lifecycle principle this way: “Incorporating this risk mitigation at the outset—beginning in the design phase and continuing through product release and updates—reduces both the burden of cybersecurity on customers and risk to the public.”
How organizations should assess vendors and products
Ask suppliers for specific evidence, not only a general assurance that a product is secure. The answers help distinguish documented, repeatable controls from claims that are difficult to verify.
- Was formal directory-traversal testing performed? Which products and versions were covered, and how is the testing repeated as products change?
- Do the tests cover CWE-22 and related variants such as CWE-23?
- What mitigations were implemented, and do they cover both current products and products still in development?
- How are path-handling controls reviewed during design, release, and updates?
- How quickly does the supplier communicate and deliver fixes, and what remediation timeline applies to any open issue?
- How does the supplier monitor KEV entries and disclose relevant issues to customers, including customers in regulated or critical-infrastructure environments?
How to use the KEV catalog in response
KEV is an exploitation-prioritization source: it helps organizations identify vulnerabilities with evidence of exploitation and focus attention on products they use. A vulnerability’s absence from KEV is not proof that a product is safe or free of path-traversal defects.
- Inventory the software products and versions your organization depends on, including products used in critical operations.
- Check CISA’s KEV catalog for relevant entries and consult the affected product’s vendor notice for the versions and mitigations that apply.
- Apply available vendor mitigations and track completion. If a mitigation is unavailable, CISA’s catalog guidance is to discontinue the affected product; treat unsupported or unmitigated products as replacement candidates.
- Ask the supplier for a clear remediation timeline where a fix or mitigation is pending, and plan around that timeline rather than assuming the issue will be resolved.
What the alert establishes—and what it does not
The May 2024 alert establishes the dated KEV count of 55 and names CVE-2024-1708 and CVE-2024-20345 as exploitation examples. It does not establish how many such vulnerabilities are in KEV today, whether a particular product is currently affected, or whether a named vendor has completed remediation. Those questions require checking current catalog entries and the supplier’s product-specific notices.
Rank #3
The alert also notes that CWE-22 appeared in MITRE’s 2023 “most dangerous” and “stubborn” weakness lists. It provides no additional count for that observation.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

