PT-2025-20282 · Sma100 · Sma100
Published
2025-05-07
·
Updated
2025-07-18
·
CVE-2025-32820
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SMA100 versions 10.2.1.14-75sv and earlier
Description
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to inject a path traversal sequence, making any directory on the SMA appliance writable.
Recommendations
For SMA100 versions 10.2.1.14-75sv and earlier, update to a version later than 10.2.1.14-75sv to resolve the issue.
As a temporary workaround, consider restricting access to SSLVPN user privileges to minimize the risk of exploitation.
Restrict access to sensitive directories on the SMA appliance to prevent potential path traversal attacks.
Fix
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sma100