CNNVD-202506-3294 Information

CNNVD ID

CNNVD-202506-3294

CVE-2025-3722

  • CNNVD Published: 2025-06-26

Description (Chinese)

Trellix System Information Reporter是美国Trellix公司的一个系统信息手机工具。 Trellix System Information Reporter 1.0.3及之前版本存在路径遍历漏洞,该漏洞源于路径遍历问题,可能导致文件系统任意文件创建或覆盖。

Description (English)

Tellix Systems Information Reporter is a system-based information cell phone tool for Trellix. There is a loophole in the Trellix System Information Reporter 1.0.3 and earlier versions, which stems from the routing problem and may lead to any file created or covered by the file system.

Hazard Level

High

Vulnerability Type

路径遍历

Affected Vendor

TreyWW

Published

2025-06-26

Last Modified

2026-02-24

References

https://thrive.trellix.com/s/article/000014635

Patch

https://docs.trellix.com/zh-CN/bundle/system-information-reporter-user-guide/resource/system-information-reporter-user-guide.pdf

Share on: