CVE-2025-40549
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
18/11/2025
Última modificación:
18/11/2025
Descripción
*** Pendiente de traducción *** A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. <br />
<br />
This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA



