Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3701

Опубликовано: 04 окт. 2023
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
EPSS Низкий

Описание

Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:aquaesolutions:aqua_drive:2.4:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.0009
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-23
CWE-22

Связанные уязвимости

CVSS3: 9.9
github
больше 2 лет назад

Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.

EPSS

Процентиль: 26%
0.0009
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-23
CWE-22