VendorsMarvellqconvergeconsoleany version
Vulnerabilities

Marvell QConvergeConsole any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2020-15639
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the decryptFile method of the FlashValidatorServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10496.
Published 2020-08-25 · Modified
10.0EPSS 0.115
CVE-2025-6794
Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability
Published 2025-07-07 · Analyzed
9.8EPSS 0.014
CVE-2025-6802
Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability
Published 2025-07-07 · Analyzed
9.8EPSS 0.006
CVE-2025-6793
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
9.4EPSS 0.173
CVE-2025-6798
Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability
Published 2025-07-07 · Analyzed
9.1EPSS 0.013
CVE-2020-15643
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the saveAsText method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10549.
Published 2020-08-25 · Modified
9.0EPSS 0.587
CVE-2020-15645
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getFileFromURL method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10553.
Published 2020-08-25 · Modified
9.0EPSS 0.107
CVE-2020-17387
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the writeObjectToConfigFile method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10565.
Published 2020-08-25 · Modified
9.0EPSS 0.101
CVE-2020-17389
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the decryptFile method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10502.
Published 2020-08-25 · Modified
9.0EPSS 0.101
CVE-2020-15644
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the setAppFileBytes method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10550.
Published 2020-08-25 · Modified
9.0EPSS 0.093
CVE-2020-17388
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10799.
Published 2020-08-25 · Modified
9.0EPSS 0.075
CVE-2020-15642
This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the isHPSmartComponent method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10501.
Published 2020-08-25 · Modified
9.0EPSS 0.072
CVE-2025-6806
Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability
Published 2025-07-07 · Analyzed
8.2EPSS 0.012
CVE-2025-6801
Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability
Published 2025-07-07 · Analyzed
8.2EPSS 0.012
CVE-2020-15641
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the FlashValidatorServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10499.
Published 2020-08-25 · Modified
7.5EPSS 0.032
CVE-2020-15640
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getFileUploadBytes method of the FlashValidatorServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10497.
Published 2020-08-25 · Modified
7.5EPSS 0.032
CVE-2025-6797
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6796
Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6799
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6800
Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6803
Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6804
Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.013
CVE-2025-6807
Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.011
CVE-2025-6795
Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability
Published 2025-07-07 · Analyzed
7.5EPSS 0.011