CVE-2013-2068 describes multiple directory traversal vulnerabilities in the AgentController of Red Hat CloudForms Management Engine 2.0. This flaw allows unauthenticated remote attackers to create or overwrite arbitrary files on the system by injecting directory traversal sequences (../) into the filename parameter of the log, upload, or linuxpkgs methods. The vulnerability has a critical CVSS score of 9.4, indicating high severity due to its network-based attack vector, low attack complexity, and complete compromise of integrity and availability. Its high EPSS and FAUCET Risk Scores further emphasize its significant potential impact. While not listed on the CISA KEV catalog, exploit intelligence confirms the existence of a Metasploit module and an ExploitDB entry for this vulnerability, demonstrating readily available exploit code. Despite this, there is no recorded community discussion or media coverage, suggesting limited public awareness or active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1CPE matchmatch criteria | cpe:2.3:a:redhat:cloudforms_management_engine:5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.