Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chr6-5733-mh8r

Опубликовано: 03 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.

EPSS

Процентиль: 69%
0.00592
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость веб-интерфейса SCADA-системы TelWin SCADA, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 69%
0.00592
Низкий

7.5 High

CVSS3

Дефекты

CWE-22