Impact
GFI Exinda AI and ClearView before 7.6.5 contain a path traversal flaw in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and concatenates these values to a base directory without sanitizing for directory traversal sequences. An authenticated attacker who has Admin privileges can supply crafted input to delete arbitrary files in the system context as root, which can destroy critical configuration, operating system files, and cause a denial‑of‑service.
Affected Systems
GFI Software’s GFI ClearView and GFI Exinda AI network orchestration platforms, versions earlier than 7.6.5, are affected. The vulnerability exists in the diagnostic module that processes file‑deletion requests through the web interface; any installation using a pre‑7.6.5 release is at risk.
Risk and Exploitability
The CVSS score of 7.0 indicates significant impact, and the weakness is classified as CWE‑22. Because the flaw requires an authenticated admin user, the attack vector is limited to users with elevated rights. However, once authorized, the attacker can delete any file on the host, effectively achieving root‑level destruction and potentially allowing further exploitation. No current public exploit is documented, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is unavailable, so the precise likelihood of exploitation is unknown, but the high severity and privileged access requirement make it a priority for patching.
OpenCVE Enrichment