There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.
Solution:
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-292-01 | us government resource third party advisory patch |