Special Element Injection Vulnerability in Intel Security VirusScan Enterprise Linux
CVE-2016-8017

4.1MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 March 2017

Summary

A special element injection vulnerability exists in Intel Security VirusScan Enterprise Linux (VSEL) versions 2.0.3 and earlier. This flaw allows authenticated remote attackers to craft specific inputs that lead to unauthorized file access on the web server. By exploiting this vulnerability, attackers can potentially read sensitive files, which may compromise the integrity and confidentiality of the system. Organizations using affected versions of VSEL should ensure they implement necessary security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)

References

EPSS Score

20% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.