CVE-2020-25842

HIGH

NHIServiSignAdapter - Unauthenticated Arbitrary File Access via Path Verification Bypass

Title source: llm
STIX 2.1

Description

The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4270-72392-1.html

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-311
Status published
Products (1)
panorama/nhiservisignadapter 1.0.20.0218
Published Dec 31, 2020
Tracked Since Feb 18, 2026