Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w54w-3cc4-mvrq

Опубликовано: 18 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость конфигурации Enable API Endpoints компонента ThinServer платформы для централизованного управления приложениями Rockwell Automation ThinManager, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-23