SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12252

The upload functionality allows an arbitrary file upload for an authenticated user.

MEDIUM 6.2EPSS 1.97%

Does this matter?

Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.

CVSS 3.1
6.2 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
EPSS
1.97% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
gigamon/gigavue
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.