cve/2020/CVE-2020-25150.md

21 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-25150](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25150)
![](https://img.shields.io/static/v1?label=Product&message=Battery%20pack%20with%20Wi-Fi&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Data%20module%20compactplus&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=SpaceCom&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%20U61%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20A10%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-23%3A%20Relative%20Path%20Traversal&color=brighgreen)
### Description
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-25150