Vulnerability Description: Path Traversal
Software Version: NOKIA IMPACT < 18A
NIST: https://nvd.nist.gov/vuln/detail/CVE-2019-17406
CVSv3: 5.3
Severity: Medium
Credits: Francesco Giordano, Alessandro Sabetta, Massimiliano Brolli
An authenticated user with access to the CDP component of NOKIA IMPACT is able to save file in arbitrary positions on the filesystem. This vulnerability was found in a feature of the system that allows to load multiple devices by uploading a properly formatted CSV file.
The filename parameter is vulnerable to a path traversal vulnerability, indeed naming the file as a relative path an attacker is able to save it in an arbitrary position on the filesystem (e.g. ../../../../../../../tmp/myfile.csv)