VulnerabilityModified
CVE-2020-12252
The upload functionality allows an arbitrary file upload for an authenticated user.
MEDIUM 6.2EPSS 1.97%
Does this matter?
Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- gigamon/gigavue
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/157484/Gigamon-GigaVUE-5.5.01.11-Directory-Traversal-File-Upload.htmlThird Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2020/Apr/56Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157484/Gigamon-GigaVUE-5.5.01.11-Directory-Traversal-File-Upload.htmlThird Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2020/Apr/56Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.