Description
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
No analysis available yet.
Remediation
Vendor Solution
Update to v4.1.12 Build 20200701 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-9338 | Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-3846-7790c-1.html |
|
History
Thu, 08 May 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system. | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system. |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-05-08T09:14:05.045Z
Reserved: 2020-08-07T00:00:00.000Z
Link: CVE-2020-17385
No data.
Status : Modified
Published: 2020-08-25T08:15:10.550
Modified: 2025-05-08T10:15:17.393
Link: CVE-2020-17385
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD