VulnerabilityModified
CVE-2022-26252
aaPanel v6.8.21 was discovered to be vulnerable to directory traversal.
MEDIUM 6.5EPSS 1.78%
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- aapanel/aapanel
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/50780Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/50780Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.