CVE-2025-5157: H3C SecCenter SMP-E1114P02 fileContent path traversal
A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file /cfgFile/fileContent. The manipulation of the argument filePath leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5157?
CVE-2025-5157 has been classified as a critical vulnerability.
How do I fix CVE-2025-5157?
To fix CVE-2025-5157, you should upgrade H3C SecCenter SMP-E1114P02 to a version released after 20250513.
What is the nature of the vulnerability described in CVE-2025-5157?
CVE-2025-5157 involves a path traversal vulnerability in the fileContent function of the /cfgFile/fileContent file.
Which systems are affected by CVE-2025-5157?
CVE-2025-5157 affects H3C SecCenter SMP-E1114P02 versions up to and including 20250513.
What type of attack can be initiated due to CVE-2025-5157?
CVE-2025-5157 can allow attackers to exploit path traversal to access unauthorized file system locations.