A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability
CVE-2023-42129

6.5MEDIUM

Key Information:

Vendor

A10

Vendor
CVE Published:
3 May 2024

What is CVE-2023-42129?

A vulnerability exists in the A10 Thunder ADC that permits remote attackers to reveal sensitive information through the ShowTechDownloadView feature. This issue arises from inadequate validation of user-supplied paths before processing file operations. Although authentication is necessary to exploit this flaw, successful attacks could allow adversaries to gain access to confidential information linked to the service account. For further details, refer to the advisory from A10 Networks and the Zero Day Initiative.

Affected Version(s)

Thunder ADC 5.2.1-p3, build 70

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.