Description
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to delete arbitrary system files or directories, resulting in data destruction or service disruption.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Product status
Any version before 1.0.4
References
www.twcert.org.tw/tw/cp-132-10969-4c4e2-1.html
www.twcert.org.tw/en/cp-139-10970-e4b21-2.html