CVE-2022-20085
published 2022-05-03CVE-2022-20085: In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
cisa7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5wfq-mm77-25rh: In netdiag, there is a possible symbolic link following due to an improper link resolution
ghsa_unreviewed·2022-05-04
CVE-2022-20085 [MEDIUM] CWE-59 GHSA-5wfq-mm77-25rh: In netdiag, there is a possible symbolic link following due to an improper link resolution
In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.
CISA
TVT NVMS-1000 Directory Traversal Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2019-20085 [HIGH] CWE-22 TVT NVMS-1000 Directory Traversal Vulnerability
Vulnerability: TVT NVMS-1000 Directory Traversal Vulnerability
Affected: TVT NVMS-1000
TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-20085
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-03
Published