CWE-37: Path Traversal: '/absolute/pathname/here'
The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-12806 — A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar
Recently published
- CVE-2024-12806 — A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar