Marvell QConvergeConsole
cpe:2.3:a:marvell:qconvergeconsole:*:*:*:*:*:*:*
- <= 5.5.0.85
A directory traversal vulnerability allowing arbitrary file deletion has been identified in Marvell QConvergeConsole. This issue arises in the deleteEventLogFile method, where user-supplied paths are not properly validated before being used in file operations. As a result, remote attackers can exploit this vulnerability to delete files with SYSTEM privileges. Notably, no authentication is required to carry out this attack.
Exploitation of this vulnerability allows for arbitrary file deletion on the affected system, with deleted files potentially being critical to system or application operation.
Marvell QConvergeConsole is no longer supported or recommended by the vendor. The product has reached End of Life and End of Support status after version 5.5.0.85 was released in January 2022.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.