Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f94-pgvg-m2ff

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename.

There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename.

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename.

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость гипервизора Huawei FusionCube, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 43%
0.00208
Низкий

Дефекты

CWE-22