vendor:
ClearSea
by:
rsp3ar
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: ClearSea
Affected Version From: 3.1.4
Affected Version To: 3.1.4
Patch Exists: NO
Related CWE: N/A
CPE: a:lifesize:clearsea:3.1.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
LifeSize ClearSea 3.1.4 Directory Traversal Vulnerabilities
LifeSize ClearSea is a client/server solution for desktop and mobile video collaboration. Version 3.1.4 has been End of Life since Jan 14 2017, and suffers from directory traversal vulnerabilities. After authenticated as admin on Control Panel, attacker will be able to 1) Download arbitrary file; 2) Upload arbitrary file (leading to code execution).
Mitigation:
Use strong password for default 'admin' user and secure management access to the device. Please consult vendor for replacement/alternative solutions.