Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a script file called "get_file.sh" which allows a user to retrieve any file stored in the "cmh-ext" folder on the device. However, the "filename" parameter is not validated correctly and this allows an attacker to directory traverse outside the /cmh-ext folder and read any file on the device. It is necessary to create the folder "cmh-ext" on the device which can be executed by an attacker first in an unauthenticated fashion and then execute a directory traversal attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vera VeraEdge和Veralite 安全漏洞
Vulnerability Description
Vera VeraEdge 1.7.19版本和Veralite 1.7.481版本中存在安全漏洞,该漏洞源于程序没有正确验证‘filename’参数。攻击者可利用漏洞遍历/cmh-ext文件夹之外的目录并读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A