CVE-2025-12382
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
12/11/2025
Last modified:
11/12/2025
Description
Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210).
Impact
Base Score 4.0
7.30
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:algosec:firewall_analyzer:a33.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:algosec:firewall_analyzer:a33.0:build320:*:*:*:*:*:* | ||
| cpe:2.3:a:algosec:firewall_analyzer:a33.10:-:*:*:*:*:*:* | ||
| cpe:2.3:a:algosec:firewall_analyzer:a33.10:build210:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:x64:* |
To consult the complete list of CPE names with products and versions, see this page



