Back to Database
Status published
High
CVE-2020-17385
Cellopoint CelloOS - Unauthenticated Arbitrary File Disclosure
Vulnerability Description
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-17385
Credits & Attribution
No credits recorded in the NVD database.
More from Cellopoint
View All →CVE-2024-9043
Cellopoint Secure Email Gateway - Buffer Overflow
Critical
9.8
CVE-2024-6744
The SMTP Listener of Secure Email Gateway from Cellopoint does...
Critical
9.8
CVE-2020-17386
Cellopoint CelloOS - Server-Side Request Forgery (SSRF)
Medium
6.5
CVE-2020-17384
Cellopoint CelloOS - Remote Command Execution (RCE)
High
7.2
Affected Vendor
Cellopoint
View all reports →Affected Software
CelloOS
Vulnerable Versions:
0
Timeline
Official Publish:
August 25th, 2020
Last Modified:
May 8th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.