An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94776 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/94776 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/94776 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04 - Third Party Advisory, US Government Resource |
Information
Published : 2017-02-13 21:59
Updated : 2024-11-21 03:00
NVD link : CVE-2016-9339
Mitre link : CVE-2016-9339
CVE.ORG link : CVE-2016-9339
JSON object : View
Products Affected
macgregor
- interschalt_vdr_g4e
- interschalt_vdr_g4e_firmware
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')