Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgvj-jh34-hqv3

Опубликовано: 03 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.

SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.

EPSS

Процентиль: 20%
0.00065
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.

CVSS3: 4.9
fstec
больше 2 лет назад

Уязвимость веб-сервера SpiderControl SCADA Web Server, существующая из-за неверного ограничения имени пути к каталогу с ограниченным доступом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 20%
0.00065
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22