Back to overview

CVE-2023-3701

CRITICAL
9.9
CVSS 3.1
Description
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.

Metadata

CVE ID
CVE-2023-3701
State
PUBLISHED
Assigner
INCIBE
Reserved
2023-07-17 07:36 UTC
Published
2023-10-04 10:56 UTC
Last updated
2024-09-19 19:22 UTC
Primary CWE
CWE-23
CWE-23: Relative Path Traversal
Vendor / Product
Aqua eSolutions / Aqua Drive
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Aqua eSolutions Aqua Drive 2.4
Weakness (CWE)
CWESourceDescription
CWE-23 cna CWE-23: Relative Path Traversal
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview