Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
2.0.0 (custom) before 2.3.13.1
affected
2.5.0.17 (custom) before 2.6.14.1
affected
2.7.0.15 (custom) before 2.9.3.6
affected
Description
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
Problem types
CWE-36 Absolute Path Traversal
Product status
2.0.0 (custom) before 2.3.13.1
2.5.0.17 (custom) before 2.6.14.1
2.7.0.15 (custom) before 2.9.3.6
Credits
Noam Moshe of Claroty Team82
References
security.samsungda.com/securityUpdates.html