D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability
CVE-2023-32167
6.5MEDIUM
Summary
A directory traversal vulnerability has been identified in D-Link D-View, specifically within the uploadMib function. The flaw arises from inadequate validation of user-supplied paths before they are utilized in critical file operations. This vulnerability permits authenticated remote attackers to create or delete arbitrary files within the affected system, potentially allowing the execution of unauthorized actions at the SYSTEM level. Organizations using D-Link D-View should prioritize proper security measures to mitigate this risk.
Affected Version(s)
D-View DLink D-View8 1.0.2.13
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved