The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
History

Mon, 18 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Trcore
Trcore dvc
CPEs cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*
Vendors & Products Trcore
Trcore dvc
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 06:45:00 +0000

Type Values Removed Values Added
Description The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Title TRCore DVC - Arbitrary File Upload through Path Traversal
Weaknesses CWE-23
CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-11-18T06:35:21.487Z

Updated: 2024-11-18T13:57:51.501Z

Reserved: 2024-11-18T01:44:52.844Z

Link: CVE-2024-11312

cve-icon Vulnrichment

Updated: 2024-11-18T13:50:29.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-18T07:15:14.903

Modified: 2024-11-18T17:11:17.393

Link: CVE-2024-11312

cve-icon Redhat

No data.