Special Element Injection Vulnerability in Intel Security VirusScan Enterprise Linux
CVE-2016-8017
4.1MEDIUM
Summary
A special element injection vulnerability exists in Intel Security VirusScan Enterprise Linux (VSEL) versions 2.0.3 and earlier. This flaw allows authenticated remote attackers to craft specific inputs that lead to unauthorized file access on the web server. By exploiting this vulnerability, attackers can potentially read sensitive files, which may compromise the integrity and confidentiality of the system. Organizations using affected versions of VSEL should ensure they implement necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)
References
EPSS Score
20% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved