CVE-2025-53080

7.1

Samsung · Data Management Server (DMS)

A path traversal vulnerability in Samsung Data Management Server allows authenticated attackers to create arbitrary files on the filesystem.

Executive summary

An authenticated path traversal vulnerability in Samsung Data Management Server poses a significant risk of arbitrary file creation, potentially leading to unauthorized system control.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) that allows an authenticated attacker to bypass directory restrictions and write files to arbitrary locations on the host filesystem. It requires the attacker to have valid access privileges to the affected server.

Business impact

The ability to create arbitrary files on the server filesystem can lead to full system compromise, including the potential for remote code execution if an attacker overwrites critical configuration files or binary executables. Given the CVSS score of 7.1, this vulnerability is classified as High severity, representing a substantial risk to data integrity and system availability.

Remediation

Immediate Action: Review the official Samsung security updates page and apply the latest available firmware or software patches for the Data Management Server as soon as they are released.

Proactive Monitoring: Monitor server logs for unusual file write operations, specifically those targeting system directories or configuration paths, and investigate any unexpected modifications to system files.

Compensating Controls: Ensure that the Data Management Server is restricted to authorized users only and implement strict principle of least privilege access controls to limit the potential impact of an authenticated user.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the high severity of this path traversal vulnerability, organizations utilizing Samsung Data Management Server must prioritize the application of security patches. Administrators should verify their current version against the affected list provided and maintain strict access controls until updates are fully deployed to mitigate the risk of unauthorized system manipulation.

More Samsung CVEs

Sources

Originally found and disclosed by Noam Moshe of Claroty Team82, per the CVE Program record.