Path traversal in Arduino Create Agent
CVE-2023-43802

7.1HIGH

Key Information:

Vendor

Arduino

Vendor
CVE Published:
18 October 2023

What is CVE-2023-43802?

A security vulnerability has been discovered in the Arduino Create Agent, which affects the /upload endpoint that processes requests with the filename parameter. This flaw allows an unauthorized user with the capability to send HTTP requests to the local interface, or to circumvent CORS settings, to escalate their privileges to that of the user running the Arduino Create Agent service. The issue has been remedied in version 1.3.3, and users are strongly advised to update their installations promptly, as there are no known workarounds to mitigate this risk.

Affected Version(s)

arduino-create-agent < 1.3.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.