Impact
A path traversal flaw exists in the log filtering feature of Riverbed SteelHead VCX appliances, allowing an authenticated user to provide specially crafted filter expressions that the backend parser expands and uses to read arbitrary files on the system. The vulnerability permits disclosure of sensitive files through the web‑based log viewer, representing a confidentiality breach (CWE‑200).
Affected Systems
Riverbed Technology’s SteelHead VCX appliances, confirmed on model VCX255U running firmware 9.6.0a, expose this flaw through the management interface’s log_filter endpoint.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high risk, while the EPSS score has dropped to < 1%, signifying a very low likelihood that the flaw is being actively exploited. Exploitation requires valid credentials to the management web interface, after which a crafted filterStr parameter is submitted to the log_filter endpoint and the system expands file references, leaking requested file content. The vulnerability is not listed in CISA’s KEV catalog, and the low exploitation probability combined with moderate severity suggests monitoring and timely patching.
OpenCVE Enrichment
EUVD