PT-2024-16905 · Trcore · Trcore Dvc

Kun Xian Lin

·

Published

2024-11-17

·

Updated

2024-11-20

·

CVE-2024-11314

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRCore DVC versions up to 6.3
Description The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Recommendations For TRCore DVC versions up to 6.3, patch systems immediately to prevent unauthorized access. As a temporary workaround, consider restricting the types of uploaded files and limiting access to sensitive directories until a patch is available. Prioritize a thorough security audit to identify any additional risks and review logs for signs of compromise.

Fix

Path traversal

Unrestricted File Upload

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2024-11314

Affected Products

Trcore Dvc