CNNVD-202507-696 Information
Jul 07, 2025
cve
CNNVD ID
CNNVD-202507-696
Related CVE
- CNNVD Published: 2025-07-07
Description (Chinese)
Marvell QConvergeConsole是美国Marvell公司的一款跨数据中心的统一适配器管理软件。 Marvell QConvergeConsole存在路径遍历漏洞,该漏洞源于saveNICParamsToFile方法未正确验证用户提供路径,可能导致任意文件写入。
Description (English)
Marvell QConvergeConsole is a United States-based multi-data centre integrated adapter management software. Marvell QConvergeConsole has a loophole in its path, which stems from the incorrect validation of the user ’ s supply path by the SaveNICParamsToFile method, which may lead to any document being written.
Hazard Level
Medium
Vulnerability Type
路径遍历
Affected Vendor
Marwal Infotech
Published
2025-07-07
Last Modified
2026-02-24
References
https://www.zerodayinitiative.com/advisories/ZDI-25-460/
Share on: