PT-2023-20541 · Unknown · Mcfeeder Server

Published

2023-10-31

·

Updated

2023-11-08

·

CVE-2023-2621

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions McFeeder server (distributed as part of SSW package) (affected versions not specified)
Description The McFeeder server is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This issue stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to the McFeeder server. An authenticated malicious client can exploit this vulnerability by uploading a crafted ZIP archive via the network to McFeeder's service endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-2621

Affected Products

Mcfeeder Server