← Back to CVEs
CVE-2020-11420
MEDIUM6.5
Description
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
CVE Details
CVSS v3.1 Score6.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published4/27/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
abb:cs141abb:cs141_firmwaregenerex:cs141generex:cs141_firmware
Weaknesses (CWE)
CWE-22
References
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(cve@mitre.org)
https://www.generex.de/support/changelogs/cs141/page:2(cve@mitre.org)
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/index.php?option=com_content&task=view&id=185&Itemid=249(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/support/changelogs/cs141/page:2(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.