CVE-2008-1310 describes a critical directory traversal vulnerability affecting the TFTP server component of PacketTrap Networks pt360 Tool Suite, specifically versions prior to 2.0.3900.0. This flaw allows unauthenticated remote attackers to read and overwrite arbitrary files on the system by injecting directory traversal sequences into file pathnames during TFTP operations. With a CVSS score of 10.0, this vulnerability is extremely severe, indicating a complete compromise of confidentiality, integrity, and availability. The attack requires no authentication and has low complexity, making it easily exploitable over the network. While there is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and no media coverage, the CVE has garnered significant community discussion, suggesting awareness and potential interest among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.33.1.0CPE matchmatch criteria | cpe:2.3:a:packettrap:pt360_tool_suite:1.1.33.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.