Path traversal in Intel Optane DC Persistent Memory - CVE-2020-0546
Published: March 16, 2020
Vulnerability identifier: #VU26086
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0546
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to escalation of privilege and denial of service.
Affected software
Intel Optane DC Persistent Memory
How to mitigate CVE-2020-0546
Install update from vendor's website.
Intel Optane DC Persistent Memory - update to 1.0.0.3461