Marvell QConvergeConsole
cpe:2.3:a:marvell:qconvergeconsole:*:*:*:*:*:*:*
- <= 5.5.0.85
A directory traversal vulnerability allowing remote information disclosure has been identified in Marvell QConvergeConsole. This issue arises in the compressDriverFiles method, where user-supplied paths are not properly validated before being used in file operations. As a result, attackers can exploit this vulnerability to access sensitive information, with the exploitation occurring in the context of the SYSTEM user. Notably, no authentication is required to exploit this vulnerability.
Exploitation of this vulnerability leads to unauthorized disclosure of sensitive information on the affected system.
Marvell QConvergeConsole is no longer supported or recommended by the vendor. The product has reached End of Life and End of Support status after version 5.5.0.85 was released in January 2022.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.