8.8
CVE-2017-17223
- EPSS 0.48%
- Veröffentlicht 09.03.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:17:41
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful exploit will upload and download files and cause information leak and system crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Espace 7910 Firmware Versionv200r003c30
Huawei ≫ Espace 7950 Firmware Versionv200r003c30
Huawei ≫ Espace 8950 Firmware Versionv200r003c00
Huawei ≫ Espace 8950 Firmware Versionv200r003c30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.48% | 0.642 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 8 | 8 | 8.5 |
AV:N/AC:L/Au:S/C:P/I:P/A:C
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.