CVE-2023-25909: HGiga Inc. OAKlouds - Arbitrary File Upload
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25909?
CVE-2023-25909 is a critical vulnerability that allows unauthenticated remote attackers to upload and execute arbitrary files.
How do I fix CVE-2023-25909?
To fix CVE-2023-25909, ensure that file upload functions restrict the upload of executable and dangerous file types.
What types of attacks can be performed using CVE-2023-25909?
An attacker can exploit CVE-2023-25909 to upload malicious files, which could lead to arbitrary command execution or service disruption.
Which software versions are affected by CVE-2023-25909?
CVE-2023-25909 affects HGiga OAKlouds Portal versions between 2.0 and 2.0-10, as well as versions between 3.0 and 3.0-10.
Is authentication required to exploit CVE-2023-25909?
No, CVE-2023-25909 can be exploited by unauthenticated remote attackers.