CVE-2019-12310

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/06/2019
Last modified:
04/06/2019

Description

ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information. Files within this directory were observed to contain sensitive run-time information, including Base64 encoded 'support' credentials, leading to administrative access of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:exagrid:backup_appliance_firmware:48.1.1044.p50:*:*:*:*:*:*:*
cpe:2.3:h:exagrid:backup_appliance:-:*:*:*:*:*:*:*