SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5804

Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability.

HIGH 8.1EPSS 1.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path prior to using it in file deletion operations. An authenticated, remote attacker can leverage this vulnerability to delete arbitrary remote files as SYSTEM or root.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
marvell/qconvergeconslole gui
Source
vulnreport@tenable.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.