Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqr5-gxvv-5ff4

Опубликовано: 24 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8

Описание

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control.

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control.

EPSS

Процентиль: 41%
0.00187
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
nvd
больше 1 года назад

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control.

EPSS

Процентиль: 41%
0.00187
Низкий

8.6 High

CVSS4

8 High

CVSS3

Дефекты

CWE-22