Impact
The Lanscope Endpoint Manager (On‑Premises) Sub‑Manager Server version 9.4.7.3 and earlier contains a path traversal flaw that allows an attacker to manipulate arbitrary files on the server and subsequently execute arbitrary code. This weakness, identified as CWE‑22, can undermine the confidentiality, integrity, and availability of the system by enabling a malicious actor to replace critical configuration or application files and run code with the server’s privileges.
Affected Systems
Motex Inc. offers the Lanscope Endpoint Manager (On‑Premises) Sub‑Manager Server. Versions up to and including 9.4.7.3 are vulnerable. No extension of the affected range is mentioned in the current data.
Risk and Exploitability
Based on the description, it is inferred that an attacker who can send requests to the Sub‑Manager Server’s HTTP interface may construct a specially crafted request that bypasses path restrictions, directing the server to overwrite system files or drop scripts that are later executed. With a CVSS score of 9.3, the vulnerability is considered critical, but the EPSS score of less than 1% indicates that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, so there is no known active exploit campaign, yet the high impact mandates prompt action.
OpenCVE Enrichment