VulnerabilityModified
CVE-2008-1410
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
MEDIUM 4.3EPSS 5.57%
Does this matter?
Lower severity and a low EPSS score (5.57%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 5.57% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- acronis/snap deploy
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/acropxe-adv.txtExploit
- http://secunia.com/advisories/29305Vendor Advisory
- http://securityreason.com/securityalert/3758
- http://www.securityfocus.com/archive/1/489358/100/0/threaded
- http://www.securityfocus.com/bid/28182Exploit
- http://www.vupen.com/english/advisories/2008/0814/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41074
- https://www.exploit-db.com/exploits/5228
- http://aluigi.altervista.org/adv/acropxe-adv.txtExploit
- http://secunia.com/advisories/29305Vendor Advisory
- http://securityreason.com/securityalert/3758
- http://www.securityfocus.com/archive/1/489358/100/0/threaded
- http://www.securityfocus.com/bid/28182Exploit
- http://www.vupen.com/english/advisories/2008/0814/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41074
- https://www.exploit-db.com/exploits/5228
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.