← Retour aux CVEs
CVE-2020-11420
MEDIUM6.5
Description
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie4/27/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
abb:cs141abb:cs141_firmwaregenerex:cs141generex:cs141_firmware
Faiblesses (CWE)
CWE-22
References
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(cve@mitre.org)
https://www.generex.de/support/changelogs/cs141/page:2(cve@mitre.org)
https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/index.php?option=com_content&task=view&id=185&Itemid=249(af854a3a-2127-422b-91ae-364da2661108)
https://www.generex.de/support/changelogs/cs141/page:2(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.