A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability
CVE-2023-42130

8.3HIGH

Key Information:

Vendor

A10

Vendor
CVE Published:
3 May 2024

What is CVE-2023-42130?

The A10 Thunder ADC is susceptible to a directory traversal vulnerability within its FileMgmtExport feature. Due to inadequate validation of user-supplied paths used in file operations, remote attackers with valid credentials may gain unauthorized access to read and delete arbitrary files on affected systems. This vulnerability could lead to significant data exposure and loss, affecting the integrity of the service account environment. Proper user input validation is crucial to mitigate this risk.

Affected Version(s)

Thunder ADC vThunder 5.2.1-p3, build 70

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.