CVE-2018-7806
Last modified
CVE-2018-7806 is a vulnerability of currently unknown severity. Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained with the zip onto the server file system outside of the intended directory. This is leveraging the more commonly known ZipSlip vulnerability within Java code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Struxureware Data Center Operation | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7806?
How severe is CVE-2018-7806?
How do I fix CVE-2018-7806?
Are you affected by CVE-2018-7806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
