Impact
This vulnerability is a directory traversal flaw in ATEN Unizon's updateLicense method, permitting authenticated attackers to manipulate the filesystem prior to performing file operations. Without proper validation of the supplied path, a malicious user can delete arbitrary files or trigger a denial‑of‑service condition, potentially undermining system integrity and availability. The weakness is identified as CWE‑22, a common exploitation vector for directory traversal attacks.
Affected Systems
ATEN Unizon devices that implement the updateLicense functionality are affected. The vulnerability requires authentication to exploit, so all existing Unizon deployments remain vulnerable until patched. No specific minor version ranges are published, so the flaw applies generically to the current software releases.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, with exploitation limited to authenticated accounts. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, suggesting limited current exploitation. An attacker gaining privileged access can submit a crafted path to updateLicense, causing deletion of critical files or a denial‑of‑service that impairs availability. The impact is bounded to the local account’s privileges but can still disrupt system operation.
OpenCVE Enrichment