Impact
The vulnerability in HGiga’s OAKlouds Bulletin allows an unauthenticated remote attacker to perform relative path traversal, enabling the reading of arbitrary system files. The flaw maps to CWE‑23: Relative Path Traversal. This can expose sensitive configuration files, secrets, or other critical data, potentially aiding further attacks such as credential theft or persistence.
Affected Systems
HGiga’s OAKlouds Bulletin version 3.2.0 and 3.3.0 are affected. The vendor’s advisory states that versions prior to 107 contain the flaw, while updates to version 107 or later provide a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of risk. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, one can infer that an attacker can send a crafted HTTP request to a vulnerable endpoint that accepts a file path parameter, thereby accessing files outside the intended directory.
OpenCVE Enrichment