Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj7m-xpw7-hcp8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.

A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.

EPSS

Процентиль: 26%
0.0009
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.4
nvd
больше 6 лет назад

A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.

CVSS3: 4.4
fstec
больше 6 лет назад

Уязвимость компонента CLI микропрограммного обеспечения контроллеров беспроводного доступа Cisco Wireless LAN Controller (WLC), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.0009
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-22