Security Advisory

CVE-2025-51463

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-22 00:00:00
Last updated 2025-07-22 17:40:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.