← Voltar para CVEs
CVE-2023-31166
MEDIUM4.1
Descricao
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system. See SEL Service Bulletin dated 2022-11-15 for more details.
Detalhes CVE
Pontuacao CVSS v3.14.1
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioREQUIRED
Publicado5/10/2023
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
selinc:sel-2241_rtac_moduleselinc:sel-2241_rtac_module_firmwareselinc:sel-3350selinc:sel-3350_firmwareselinc:sel-3505selinc:sel-3505-3selinc:sel-3505-3_firmwareselinc:sel-3505_firmwareselinc:sel-3530selinc:sel-3530-4selinc:sel-3530-4_firmwareselinc:sel-3530_firmwareselinc:sel-3532selinc:sel-3532_firmwareselinc:sel-3555selinc:sel-3555_firmwareselinc:sel-3560eselinc:sel-3560e_firmwareselinc:sel-3560sselinc:sel-3560s_firmware
Fraquezas (CWE)
CWE-22CWE-22
Referencias
https://selinc.com/support/security-notifications/external-reports/(security@selinc.com)
https://www.nozominetworks.com/blog/(security@selinc.com)
https://selinc.com/support/security-notifications/external-reports/(af854a3a-2127-422b-91ae-364da2661108)
https://www.nozominetworks.com/blog/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.