WaveStore WaveView Client Path Traversal Vulnerability Allowing File Manipulation on WaveStore Server
Vulnerability
A path traversal vulnerability has been identified in the WaveView client, allowing high-privileged attackers to read or delete files on the connected WaveStore Server. This issue arises in the 'alog' script, where improper validation of file paths can be exploited to access or modify files with the permissions of the 'dvr' user. The vulnerability affects all versions of WaveStore Server prior to 6.44.44.
Impact
Exploitation of this vulnerability allows for unauthorized reading or deletion of files on the WaveStore Server, potentially leading to loss of critical data or disruption of services.
Remediation
Users can upgrade to WaveStore Server version 6.44.44 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
