← Zuruck zu CVEs
CVE-2020-11420
MEDIUM6.5
Beschreibung
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht4/27/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
abb:cs141abb:cs141_firmwaregenerex:cs141generex:cs141_firmware
Schwachen (CWE)
CWE-22
Referenzen
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(cve@mitre.org)
https://www.generex.de/support/changelogs/cs141/page:2(cve@mitre.org)
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/index.php?option=com_content&task=view&id=185&Itemid=249(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/support/changelogs/cs141/page:2(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.