Impact
Gigamon GVOS software contains a directory traversal flaw in its H‑VUE subsystem, allowing an attacker to craft file paths that escape the intended directory boundary. This weakness can lead to unauthorized reading or modification of files located outside the controlled application area, potentially exposing sensitive configuration data or compromising system integrity. The underlying vulnerability corresponds to CWE‑22 Path Traversal.
Affected Systems
Gigamon GVOS versions 5.16.1 and earlier are affected, specifically the H‑VUE subsystem component. No other Gigamon products or third‑party systems are known to share this flaw.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data. Nonetheless, if the H‑VUE interface is reachable from untrusted networks, an attacker could potentially send a crafted request to traverse directories, read protected files, or write to them if write privileges are present. With a CVSS score of 7.5, the vulnerability is considered high severity, but the potential for confidentiality or integrity compromise warrants caution.
OpenCVE Enrichment