MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-53081

CVSS 6.4v3.1pub. 2025-07-29upd. 2025-08-11

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Samsung Data Management Server

    HW
    Samsung
    all versions
  • Samsung Data Management Server Firmware

    OS
    Samsung
    2.0.0 – 2.3.13.1 (excl.)2.5.0.17 – 2.6.14.1 (excl.)2.7.0.15 – 2.9.3.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-53078HIGH8.0same product

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary...

CVE-2025-53080HIGH7.1same product

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management ...

CVE-2010-4284HIGH7.5same product

SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Ser...

CVE-2025-53077MEDIUM6.5same product

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functio...

CVE-2025-53079MEDIUM4.9same product

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) t...