Security Advisory

CVE-2020-7478

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-23 19:17:11
Last updated 2024-08-04 09:33:18
Assigner schneider
State PUBLISHED

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled.