2.2
CVSSv3

CVE-2020-12251

Published: 29/04/2020 Updated: 18/05/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 2.2 | Impact Score: 1.4 | Exploitability Score: 0.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, obtain a complete directory listing of the machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gigamon gigavue

Exploits

Gigamon GigaVUE version 550111 suffers from directory traversal and file upload with command execution vulnerabilities Gigamon has chosen to sunset this product and not offer a patch ...