ZeroHour

CVE-2023-45277

PoC
CVSS 3.1
7.5 high
EPSS
1%p61
Published
()
Modified
Description

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

Vendors
spaceapplications
Products
yamcs
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.