File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.
The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bf-os | Bosch | 3.00 (including) | 3.83 (including) |