CVE-2020-12252

EUVD-2020-4566
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
gigamongigavue
5.4 ≤
𝑥
< 5.4.04
gigamongigavue
5.5 ≤
𝑥
< 5.5.02
gigamongigavue
5.6 ≤
𝑥
< 5.6.02
gigamongigavue
5.7 ≤
𝑥
< 5.7.04
gigamongigavue
5.8 ≤
𝑥
< 5.8.02
gigamongigavue
5.9 ≤
𝑥
< 5.9.00.04
𝑥
= Vulnerable software versions