VYPR

Qconvergeconslole Gui

by Marvell

CVEs (2)

  • CVE-2020-5805HigJan 8, 2021
    risk 0.57cvss 8.8epss 0.01

    In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.

  • CVE-2020-5804HigJan 8, 2021
    risk 0.53cvss 8.1epss 0.02

    Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path prior to using it in file deletion operations. An authenticated, remote attacker…