A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file /cfgFile/fileContent. The manipulation of the argument filePath leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://flowus.cn/share/f78256ea-f210-4b35-ba71-85aba82d3e0a?code=G8A6P3 | Permissions Required |
https://vuldb.com/?ctiid.310245 | Permissions Required VDB Entry |
https://vuldb.com/?id.310245 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.576229 | Third Party Advisory VDB Entry |
Configurations
History
03 Jun 2025, 15:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:h3c:seccenter_smp-1114p02:*:*:*:*:*:*:*:* | |
References | () https://flowus.cn/share/f78256ea-f210-4b35-ba71-85aba82d3e0a?code=G8A6P3 - Permissions Required | |
References | () https://vuldb.com/?ctiid.310245 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310245 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.576229 - Third Party Advisory, VDB Entry | |
First Time |
H3c seccenter Smp-1114p02
H3c |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 May 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-25 23:15
Updated : 2025-06-03 15:49
NVD link : CVE-2025-5157
Mitre link : CVE-2025-5157
CVE.ORG link : CVE-2025-5157
JSON object : View
Products Affected
h3c
- seccenter_smp-1114p02
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')