Security Advisory

CVE-2018-15486

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-09-07 22:00:00
Last updated 2024-08-05 09:54:03
Assigner mitre
State PUBLISHED

Description

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka KONE-02.