PT-2020-13073 · Gigamon · Gigavue
Balazs Hambalko
·
Published
2020-04-29
·
Updated
2020-05-18
·
CVE-2020-12251
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gigamon GigaVUE version 5.5.01.11
Description
An issue was discovered in the upload functionality, allowing an authenticated user to change the filename value in the POST method to achieve directory traversal via a ../ sequence. This could potentially allow an attacker to obtain a complete directory listing of the machine.
Recommendations
For Gigamon GigaVUE version 5.5.01.11, consider restricting access to the upload functionality until a patch is available. As a temporary workaround, avoid using the filename value in the POST method to prevent directory traversal attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gigavue