HIGH · 7.8

CVE-2013-3574

Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathn...

Vulnerability Description

Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:C/A:N
Confidentiality
NONE
Integrity
COMPLETE
Availability
NONE

Affected Products

VendorProductVersions
HpInsight Diagnostics9.4.0.4710

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3574?

CVE-2013-3574 is a vulnerability with a CVSS score of 7.8 (HIGH). Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathn...

How severe is CVE-2013-3574?

CVE-2013-3574 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3574?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Insight Diagnostics.