CRITICAL
HGiga Inc. OAKlouds - Arbitrary File Upload
Published Mar 27, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.94%
Description
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
Affected products
-
Affected
- 2
- 3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Hgiga Inc. | HGiga OAKlouds | unknown | Affected
|
OR
- ≥ 2.0 · < 2.0-10
- ≥ 3.0 · < 3.0-10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
- Update OAKlouds-layout-2.0 to OAKlouds-layout-2.0-10 - Update OAKlouds-layout-3.0 to OAKlouds-layout-3.0-10
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-29797 Advisory
- https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-29797 | Advisory | |
| https://www.twcert.org.tw/tw/cp-132-6973-45872-1.html | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Mar 27, 2023
Updated Feb 19, 2025
Reserved Feb 16, 2023
Link CVE-2023-25909
CISA Vulnrichment
Updated Feb 19, 2025
Red Hat
No data
GitHub
No data