Описание
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0.rib4 (включая) до 4.0.6.ris1 (включая)Версия от 4.1.0.rhu2 (включая) до 4.2.3.rk91 (исключая)
Одно из
cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*
cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.0031
Низкий
8.5 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 8.5
github
больше 2 лет назад
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
EPSS
Процентиль: 54%
0.0031
Низкий
8.5 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-22
CWE-22