Home
HIGH: 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:HDefault status
unaffected
2.0.0 (custom) before 2.3.13.1
affected
2.5.0.17 (custom) before 2.6.14.1
affected
2.7.0.15 (custom) before 2.9.3.6
affected
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
2.0.0 (custom) before 2.3.13.1
2.5.0.17 (custom) before 2.6.14.1
2.7.0.15 (custom) before 2.9.3.6
Credits
Noam Moshe of Claroty Team82
References
security.samsungda.com/securityUpdates.html