Impact
This vulnerability resides in the handling of AIP files in PAX Technology™ Q80, where an attacker can craft a symbolic link to cause the installer process to write arbitrary files. The flaw qualifies as a path traversal or relative path exploitation (CWE‑59) and grants the attacker the ability to execute code, potentially as root, when combined with other weaknesses. The impact is a full compromise of the affected system’s confidentiality, integrity, and availability.
Affected Systems
The only explicitly listed affected product is PAX Technology Q80. No specific version numbers were provided, so any installation of Q80 that implements AIP file parsing without mitigations is considered at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, and the lack of authentication requirements means that any network‑adjacent attacker could trigger the exploit. EPSS is not available, but the vulnerability is not listed in CISA KEV, suggesting no publicly known exploited instances yet. The likely attack vector is a network‑adjacent attacker delivering a crafted AIP file to the installer, resulting in symbolic link exploitation and possible privilege escalation to root.
OpenCVE Enrichment