VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,481)

page 228 of 525
  • CVE-2023-33878MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32655MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Path transversal in some Intel(R) NUC Kits & Mini PCs - NUC8i7HVK & NUC8HNK USB Type C power delivery controller installatio software before version 1.0.10.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-32278MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Path transversal in some Intel(R) NUC Uniwill Service Driver for Intel(R) NUC M15 Laptop Kits - LAPRC510 & LAPRC710 Uniwill Service Driver installation software before version 1.0.1.7 for Intel(R) NUC Software Studio may allow an authenticated user to potentially enable…

  • CVE-2022-27229MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-26736MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.

  • CVE-2023-35185MedOct 19, 2023
    risk 0.44cvss 6.8epss 0.01

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.

  • CVE-2022-33165MedOct 14, 2023
    risk 0.44cvss 6.8epss 0.02

    IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.

  • CVE-2023-40930MedSep 20, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.

  • CVE-2023-38256MedSep 11, 2023
    risk 0.44cvss 6.8epss 0.01

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 vulnerable to a path traversal attack, which could allow an attacker to access files stored on the system.

  • CVE-2023-39139HigAug 30, 2023
    risk 0.44cvss 7.8epss 0.00

    An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.

  • CVE-2023-34125MedJul 13, 2023
    risk 0.44cvss 6.5epss 0.25

    Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-25307HigJun 26, 2023
    risk 0.44cvss 7.8epss 0.01

    nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.

  • CVE-2023-1864MedJun 7, 2023
    risk 0.44cvss 6.8epss 0.01

    FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacker to remotely read files on the system running the affected software.

  • CVE-2022-34855MedMay 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25508MedApr 22, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information…

  • CVE-2022-43771MedApr 3, 2023
    risk 0.44cvss 6.5epss 0.24

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.  

  • CVE-2023-1009MedFeb 24, 2023
    risk 0.44cvss 6.5epss 0.16

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function sub_1DF14 of the file /cgi-bin/mainfunction.cgi of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-0745MedFeb 9, 2023
    risk 0.44cvss 6.7epss 0.01

    The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files…

  • CVE-2022-37934MedJan 5, 2023
    risk 0.44cvss 6.8epss 0.02

    A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotely exploited to allow remote directory traversal in HPE OfficeConnect 1820 switch series version PT.02.17 and below, HPE OfficeConnect 1850…

  • CVE-2022-40607MedDec 19, 2022
    risk 0.44cvss 6.8epss 0.01

    IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.