Количество 3
Количество 3
CVE-2024-47563
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.
GHSA-6j87-vf5h-vj72
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.
BDU:2024-09670
Уязвимость приложения для мониторинга безопасности сети Siemens SINEC Security Monitor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю создать файлы в произвольных каталогах
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-47563 A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-6j87-vf5h-vj72 A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
BDU:2024-09670 Уязвимость приложения для мониторинга безопасности сети Siemens SINEC Security Monitor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю создать файлы в произвольных каталогах | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу