PoC Index

CVE-2023-45277

HIGH 7.5EPSS 1.0%

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.00% chance of exploitation in the next 30 days, 61th percentile
Published
2023-10-19
Updated
2024-08-02

Proof-of-concept exploits (2)

References

Related