Impact
The flaw resides in the ImportDeviceList method, where an attacker, after authenticating, can supply an unsanitized file path that the system uses for file operations. This directory traversal leads to arbitrary code being executed with SYSTEM privileges. The vulnerability belongs to CWE-22. The impact is the ability to run any code on the affected ATEN Unizon installation.
Affected Systems
ATEN Unizon devices are affected. No specific version information is listed in the advisory.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. EPSS data is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, but it requires authentication, so only authenticated users can leverage it, which narrows the threat surface. Attackers would first gain valid credentials and then invoke the vulnerable ImportDeviceList functionality to trigger the traversal and execute code.
OpenCVE Enrichment