Vulnerability Description
Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flexense | Diskboss | 7.7.14 |
Related Weaknesses (CWE)
References
- https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/diskboss_setup_v7.7.1Product
- https://www.diskboss.com/Product
- https://www.exploit-db.com/exploits/48276ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/flexsense-diskboss-denial-of-service-by-craThird Party Advisory
FAQ
What is CVE-2020-36882?
CVE-2020-36882 is a vulnerability with a CVSS score of 7.5 (HIGH). Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.
How severe is CVE-2020-36882?
CVE-2020-36882 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36882?
Check the references section above for vendor advisories and patch information. Affected products include: Flexense Diskboss.