Home
MEDIUM: 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HDefault status
unaffected
2.0.0 (custom) before 2.3.13.1
affected
2.5.0.17 (custom) before 2.6.14.1
affected
2.7.0.15 (custom) before 2.9.3.6
affected
Description
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
Problem types
CWE-23 Relative Path Traversal
Product status
2.0.0 (custom) before 2.3.13.1
2.5.0.17 (custom) before 2.6.14.1
2.7.0.15 (custom) before 2.9.3.6
Credits
Noam Moshe of Claroty Team82
References
security.samsungda.com/securityUpdates.html