Impact
The vulnerability resides in the LoadImageAsPngBase64 endpoint of Newell Brands DYMO Connect Desktop. It accepts a file path parameter without adequate validation, enabling the caller to supply a crafted path that allows the service to read any image file on the host filesystem that matches an allowed extension. This flaw permits an attacker with local access to read arbitrary image files outside the intended directory scope, potentially leading to unauthorized disclosure of the image content.
Affected Systems
Newell Brands: DYMO Connect Desktop versions prior to 1.6.2 are affected. The fix in version 1.6.2 limits access by file extension only, but does not restrict directory location, so the residual risk of reading any file with an accepted image extension remains.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as medium severity, while the EPSS < 1% indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The service; an adversary needs the ability to issue requests to the internal service, typically by being on the same machine or having compromised credentials to communicate with the application. No privileged access is required beyond the ability to call the service, but the ability to read sensitive files may depend on the file system permissions of the service process.
OpenCVE Enrichment