GPU VulnDB

Database/Control plane, storage & DevOps

A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directory

CVE-2023-42130Control plane, storage & DevOpsZDI-23-1496curated

Impact

An authenticated attacker can walk outside the intended export directory via the FileMgmtExport component, reading or deleting arbitrary files on the ADC — enough to pull sensitive configuration data or sabotage the device by deleting files it depends on.

Who can reach it

Requires authentication to the management interface, then a crafted path sent to the file-export functionality.

What to do

Software upgrade to the fixed ACOS release per A10's security advisory. Standard upgrade-and-reboot per Thunder ADC instance; coordinate with failover if this device is in the active traffic path for a cluster.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.