Fiche vulnérabilité
CVE-2023-45278 : faille critique spaceapplications yamcs (CVSS 9.1)
Description
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.
En bref
- Sévérité
- Critique (CVSS 9.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 oct. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- spaceapplications yamcs