CVE-2024-8685: Path-Traversal vulnerability in Revolution Pi

Medium (4.3)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.

Classification

CVE ID: CVE-2024-8685

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: KUNBUS GmbH

Product: Revolution Pi

Timeline