Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210).

Project Subscriptions

Vendors Products
Algosec Subscribe
Firewall Analyzer Subscribe
Linux Kernel Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade ASMS suite to A33.0 (330 and above), A33.10 (220 and above). https://portal.algosec.com/en/downloads/hotfix_releases


Workaround

No workaround given by the vendor.

History

Thu, 11 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 11 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:algosec:firewall_analyzer:a33.0:-:*:*:*:*:*:*
cpe:2.3:a:algosec:firewall_analyzer:a33.0:build320:*:*:*:*:*:*
cpe:2.3:a:algosec:firewall_analyzer:a33.10:-:*:*:*:*:*:*
cpe:2.3:a:algosec:firewall_analyzer:a33.10:build210:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:x64:*
Vendors & Products Linux
Linux linux Kernel
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Thu, 13 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows Path Traversal, Code Injection.This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210). Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210).

Wed, 12 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Algosec
Algosec firewall Analyzer
Vendors & Products Algosec
Algosec firewall Analyzer

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows Path Traversal, Code Injection.This issue affects Algosec Firewall Analyzer: A33.0 (up to build 320), A33.10 (up to build 210).
Title Path Traversal Allows Remote Code Execution in AlgoSec Firewall Analyzer
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/RE:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2025-11-13T10:48:50.053Z

Reserved: 2025-10-28T09:05:58.212Z

Link: CVE-2025-12382

cve-icon Vulnrichment

Updated: 2025-11-12T14:17:34.765Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-12T10:15:43.100

Modified: 2025-12-11T18:37:02.267

Link: CVE-2025-12382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T22:12:42Z

Weaknesses