Логотип exploitDog
bind:CVE-2024-47563
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47563

Количество 3

Количество 3

nvd логотип

CVE-2024-47563

больше 1 года назад

A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6j87-vf5h-vj72

больше 1 года назад

A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-09670

больше 1 года назад

Уязвимость приложения для мониторинга безопасности сети Siemens SINEC Security Monitor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю создать файлы в произвольных каталогах

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-47563

A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-6j87-vf5h-vj72

A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-09670

Уязвимость приложения для мониторинга безопасности сети Siemens SINEC Security Monitor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю создать файлы в произвольных каталогах

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу