SIOS Technology Quick Agent Path Traversal Vulnerability in File Download Function
Vulnerability
A path traversal vulnerability has been identified in Quick Agent V3 versions prior to 3.2.1 and Quick Agent V2 versions prior to 2.9.8. This vulnerability allows a remote attacker with login access to the affected product to download arbitrary files from the system where Quick Agent is installed.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the user's PC or server.
Remediation
Users are advised to update Quick Agent to the latest version: Quick Agent V3 to version 3.2.1 or later, and Quick Agent V2 to version 2.9.8 or later. The latest versions can be downloaded from the SIOS MFP Support Site.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
