ID

VAR-202106-2293


TITLE

Arbitrary file reading vulnerability exists in MAS mobile proxy server

Trust: 0.6

sources: CNVD: CNVD-2021-30903

DESCRIPTION

Mobile Proxy Server (MAS) is the abbreviation of Mobile Agent Server. It is an access tool that assists the enterprise's original business system to realize wireless applications. After the MAS is connected, the enterprise's original business system can easily implement wireless applications, such as: OA system Can realize mobile office, email notification, mobile approval, etc. The MAS mobile proxy server has an arbitrary file reading vulnerability, which can be exploited by attackers to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-30903

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-30903

AFFECTED PRODUCTS

vendor: - model:mobile communications limited mas mobile proxy serverscope:eqversion:2.0

Trust: 0.6

sources: CNVD: CNVD-2021-30903

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-30903
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-30903
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-30903

EXTERNAL IDS

db:CNVDid:CNVD-2021-30903

Trust: 0.6

sources: CNVD: CNVD-2021-30903

SOURCES

db:CNVDid:CNVD-2021-30903

LAST UPDATE DATE

2022-05-04T09:32:25.995000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-30903date:2021-04-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-30903date:2021-06-01T00:00:00