Impact
Scirius through version 3.8.0 allows users with the default User role to write arbitrary JSON files to the operating system’s filesystem by uploading a PCAP via the REST API. The flaw lies in the filestore upload endpoint, which accepts an _id field that can contain path traversal sequences. Attackers can craft this field to escape the designated upload directory and place files with a .json extension at any location, effectively writing to arbitrary paths as the root user. This allows modification of configuration files, execution of malicious scripts, or other actions that compromise confidentiality, integrity, and availability.
Affected Systems
The affected product is Scirius from Stamus Networks. Versions up to and including 3.8.0 are vulnerable; any release beyond 3.8.0 is expected to contain the fix. The vulnerability is exercised only when the user role has default User permissions, so systems that restrict upload functionality to administrators may be less directly impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating moderate to high severity, but the EPSS score is less than 1 per cent, suggesting current exploitation activity is very low. It is not listed in CISA’s KEV catalog. The attack vector is remote via the REST API; an attacker must be able to authenticate as a default User and upload a PCAP file, but no additional network or local privileges are required beyond the normal API access. Once the exploit is executed, the attacker can write files anywhere on the host, enabling potential privilege escalation or persistence.
OpenCVE Enrichment