Lucene search

K
cveDellCVE-2018-11051
HistoryJul 03, 2018 - 5:29 p.m.

CVE-2018-11051

2018-07-0317:29:00
CWE-22
dell
web.nvd.nist.gov
27
rsa
certificate manager
vulnerability
path traversal
nvd
cve-2018-11051

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

54.5%

RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

Affected configurations

Nvd
Node
emcrsa_certificate_managerRange6.9
VendorProductVersionCPE
emcrsa_certificate_manager*cpe:2.3:a:emc:rsa_certificate_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Certificate Manager Path Traversal Vulnerability",
    "vendor": "RSA",
    "versions": [
      {
        "status": "affected",
        "version": "6.9 build 560 through 6.9 build 564"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

54.5%

Related for CVE-2018-11051