ZDI-CAN-17905: ZDI-23-1496: A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability
This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw exists within the FileMgmtExport class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to read and delete files in the context of the service account.
Other sources
This vulnerability allows remote attackers to read and delete arbitrary files on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.3. The following CVEs are assigned: CVE-2023-42130.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-17905?
The severity of ZDI-CAN-17905 is critical due to its potential to allow remote attackers to access sensitive files.
How do I fix ZDI-CAN-17905?
To fix ZDI-CAN-17905, ensure that all affected versions of A10 Thunder ADC are updated to the latest patches provided by A10 Networks.
What type of access does ZDI-CAN-17905 allow attackers?
ZDI-CAN-17905 allows authenticated remote attackers to read and delete arbitrary files on affected installations.
Is authentication required to exploit ZDI-CAN-17905?
Yes, authentication is required to exploit ZDI-CAN-17905.
Which product is affected by ZDI-CAN-17905?
A10 Thunder ADC is the affected product for ZDI-CAN-17905.