8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.
Basic Information
ID
CVE-2025-58072
Source
jpcert
Published
Aug 28, 2025 at 08:28
Affected Product
Vendor
DOS Co., Ltd.
Product
SS1
Version
Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under MacOS environment only)
Affected Versions
DOS Co., Ltd. SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under MacOS environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under MacOS environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under MacOS environment only)