VYPR

Gigavue

by Gigamon

CVEs (2)

  • CVE-2020-12252MedApr 29, 2020
    risk 0.40cvss 6.2epss 0.02

    An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.

  • CVE-2020-12251LowApr 29, 2020
    risk 0.14cvss 2.2epss 0.01

    An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, obtain a complete…