Impact
ArcGIS Server allows unauthenticated users to upload arbitrary files to a privileged endpoint. The attacker can place malicious files on the server, potentially enabling code execution or data exfiltration if the files are later accessed or executed by other components. The vulnerability is a classic Unvalidated File Upload issue identified as CWE‑434, which permits the attacker to influence the type and content of files received by the application.
Affected Systems
The affected vendor is Esri, specifically its ArcGIS Server product. All versions of ArcGIS Server running on Windows and Linux up to and including version 12.0 are impacted. ArcGIS Enterprise for Kubernetes is not affected.
Risk and Exploitability
The CVSS score of 9.8 denotes critical severity, while the EPSS score of <1% suggests a very low probability of exploitation. The flaw is not flagged in the CISA KEV catalog. The likely attack vector is through the publicly reachable endpoint. If an attacker succeeds, the vulnerability permits uploading arbitrary files, which could be used to execute further attacks or infiltrate the system with malicious content.
OpenCVE Enrichment