{ "id": "CVE-2016-8206", "sourceIdentifier": "sirt@brocade.com", "published": "2017-01-14T19:59:00.273", "lastModified": "2018-05-10T01:29:01.440", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files." }, { "lang": "es", "value": "Una vulnerabilidad de salto de directorio en el servlet SoftwareImageUpload en las versiones Brocade Network Advisor liberadas anteriormente e incluyendo a la 14.0.2 podr\u00edan permitir a atacantes remotos escribir archivos arbitrarios, y consecuentemente eliminar los archivos." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.4 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-22" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:brocade:network_advisor:*:*:*:*:*:*:*:*", "versionEndIncluding": "14.0.2", "matchCriteriaId": "549F2607-DC42-46B1-AC0E-353C252EA3CB" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/95692", "source": "sirt@brocade.com", "tags": [ "Third Party Advisory", "VDB Entry" ] }, { "url": "http://www.zerodayinitiative.com/advisories/ZDI-17-051", "source": "sirt@brocade.com" }, { "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03785en_us", "source": "sirt@brocade.com" }, { "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-179", "source": "sirt@brocade.com" } ] }