VulnerabilityModified
CVE-2013-6030
Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the…
MEDIUM 5.0EPSS 2.94%
Does this matter?
Lower severity and a low EPSS score (2.94%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.94% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- emerson/network power avocent mergepoint unity 2016 firmware
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/168751US Government Resource
- http://www.securityfocus.com/bid/65105
- http://www.kb.cert.org/vuls/id/168751US Government Resource
- http://www.securityfocus.com/bid/65105
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.