PT-2020-13073 · Gigamon · Gigavue

Balazs Hambalko

·

Published

2020-04-29

·

Updated

2020-05-18

·

CVE-2020-12251

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gigamon GigaVUE version 5.5.01.11
Description An issue was discovered in the upload functionality, allowing an authenticated user to change the filename value in the POST method to achieve directory traversal via a ../ sequence. This could potentially allow an attacker to obtain a complete directory listing of the machine.
Recommendations For Gigamon GigaVUE version 5.5.01.11, consider restricting access to the upload functionality until a patch is available. As a temporary workaround, avoid using the filename value in the POST method to prevent directory traversal attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12251

Affected Products

Gigavue