Path traversal in Intel Optane DC Persistent Memory - CVE-2020-0546

 

Path traversal in Intel Optane DC Persistent Memory - CVE-2020-0546

Published: March 16, 2020


Vulnerability identifier: #VU26086
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0546
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read arbitrary files on the system, leading to escalation of privilege and denial of service.


Affected software

Intel Optane DC Persistent Memory

How to mitigate CVE-2020-0546

Install update from vendor's website.

Intel Optane DC Persistent Memory - update to 1.0.0.3461

External References

Related Security Bulletins