H3C SecCenter Path Traversal Vulnerability in SafeEvent Download Function

Vulnerability

A path traversal vulnerability has been identified in H3C SecCenter SMP-E1114P02 versions prior to 20250513. The issue arises in the operationDailyOut function within the safeEvent/download file, where improper handling of the filename argument allows for directory traversal. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for path traversal, potentially leading to unauthorized access to files on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.