CVE-2023-2909: A Directory traversal vulnerability was found on EZ Sync service of ADM
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-2909.
What is the title of this vulnerability?
The title of this vulnerability is 'EZ Sync service fails to adequately handle user input allowing an attacker to navigate beyond the intended directory structure and delete files'.
What is the severity of CVE-2023-2909?
The severity of CVE-2023-2909 is critical (10).
Which software versions are affected by CVE-2023-2909?
The affected software versions include ADM 4.0.6.REG2, 4.1.0 and below, as well as ADM 4.2.1.RGE2 and below.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by manipulating user input to navigate beyond the intended directory structure and delete files.