PT-2023-6115 · A10 · A10 Thunder Adc

Chudypb

+1

·

Published

2023-10-04

·

Updated

2025-08-18

·

CVE-2023-42129

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions A10 Thunder ADC (affected versions not specified)
Description This issue allows remote attackers to disclose sensitive information on affected installations of A10 Thunder ADC. The specific flaw exists within the ShowTechDownloadView class, resulting from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the service account. Authentication is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-06821
CVE-2023-42129
ZDI-23-1495

Affected Products

A10 Thunder Adc