Path traversal in CivetWeb - CVE-2020-27304
Published: March 11, 2022
Vulnerability identifier: #VU61251
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27304
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the mg_handle_form_request API. A remote attacker can send a specially crafted HTTP request and upload arbitrary files on the system.
Affected software
CivetWeb
SINEC INS
SCALANCE LPE9403
Red Hat Advanced Cluster Security for Kubernetes
SINEC INS
SCALANCE LPE9403
Red Hat Advanced Cluster Security for Kubernetes
How to mitigate CVE-2020-27304
Install update from vendor's website.
CivetWeb - update to 1.15
SINEC INS - update to 1.0.1.1
SCALANCE LPE9403 - update to 2.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
SINEC INS - update to 1.0.1.1
SCALANCE LPE9403 - update to 2.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67