CVE-2025-5161: H3C SecCenter SMP-E1114P02 download operationDailyOut path traversal
A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file /safeEvent/download. The manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5161?
CVE-2025-5161 is classified as problematic, indicating a moderate level of security risk.
What impact does CVE-2025-5161 have on the system?
CVE-2025-5161 allows attackers to exploit a path traversal vulnerability through the filename argument.
How do I fix CVE-2025-5161?
To fix CVE-2025-5161, upgrade H3C SecCenter SMP-E1114P02 to a version after 20250513.
Which versions of H3C SecCenter are affected by CVE-2025-5161?
H3C SecCenter SMP-E1114P02 up to and including version 20250513 is affected by CVE-2025-5161.
Is CVE-2025-5161 easy to exploit?
The path traversal nature of CVE-2025-5161 can make it potentially easy to exploit if proper security measures are not in place.