Suprema BioStar 2
cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*
- >= 2.9.3, <= 2.9.11
A vulnerability exists in Suprema BioStar 2 versions 2.9.3 through 2.9.11, due to incorrect permission settings on a critical resource. This flaw allows backup files to be publicly accessible when the administrator specifies their path within the NGINX webroot. As a result, an attacker with network access can directly download backup ZIP files without authentication, exposing highly sensitive information that could lead to server impersonation, unauthorized database access, and lateral movement within the network.
Exploitation of this vulnerability allows for unauthorized access to backup files containing sensitive information, which could be used for server impersonation, unauthorized database access, and lateral movement within the network.
Users are advised to update to the latest available version of Suprema BioStar 2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.