Impact
A path traversal flaw exists in the system maintenance configuration download handler of GFI Exinda AI and GFI ClearView versions earlier than 7.6.5. The wcf_handle_download function accepts v_del_ prefixed parameters and concatenates them directly to the base configuration directory without sanitizing directory traversal characters. An attacker who is authenticated and holds administrative privileges can exploit this behavior to read any file on the host in the context of the root user, resulting in a confidentiality compromise.
Affected Systems
Both GFI Software products, GFI Exinda AI and GFI ClearView, are affected when deployed with any version earlier than 7.6.5. Only users with authenticated administrative access are in scope for exploitation; non‑admin users cannot trigger the vulnerable download handler.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate admin credentials, limiting the attack surface to local or network administrators. Once authenticated, the attacker gains the ability to read arbitrary root files, which can lead to significant information disclosure and potential pivoting into further system compromise.
OpenCVE Enrichment