SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7858

There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92.

HIGH 8.6EPSS 1.06%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause information leakage.

CVSS 3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-548, CWE-22
Affected
cdnetworks/aquanplayer
Source
vuln@krcert.or.kr

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.