CVE-2025-32820: Path Traversal
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32820?
CVE-2025-32820 has a high severity rating due to the potential for remote authenticated attackers to gain unauthorized access to directories.
How do I fix CVE-2025-32820?
To fix CVE-2025-32820, apply the latest security patches provided by SMA for the SMA100 appliance.
Who is affected by CVE-2025-32820?
The vulnerability affects users with SSLVPN privileges on the SMA100 appliance.
What is the impact of CVE-2025-32820?
CVE-2025-32820 allows attackers to inject a path traversal sequence, leading to unauthorized write access to any directory on the SMA appliance.
Is there a workaround for CVE-2025-32820?
Currently, implementing strict access controls and limiting user privileges can serve as a temporary workaround for CVE-2025-32820.