First published: Tue Aug 25 2020(Updated: )
Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Cellopoint Cellos | =4.1.10-build20190922 |
Update to v4.1.12 Build 20200701 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17385 is a vulnerability in Cellopoint Cellos v4.1.10 Build 20190922 that allows unauthorized users to launch a Path Traversal attack and access arbitrary files on the system.
The severity of CVE-2020-17385 is high with a severity value of 7.5.
CVE-2020-17385 affects Cellopoint Cellos v4.1.10 Build 20190922 by not properly validating URL input, which allows for the exploitation of a Path Traversal vulnerability.
The CVE-2020-17385 vulnerability can be exploited by an unauthorized user launching a Path Traversal attack and gaining access to arbitrary files on the system.
At the time of writing, there is no specific fix available for CVE-2020-17385. It is recommended to update to a version of Cellopoint Cellos that addresses this vulnerability, if and when it becomes available.