CVE-2016-9364

An issue was discovered in Fidelix FX-20 series controllers, versions prior to 11.50.19. Arbitrary file reading via path traversal allows an attacker to access arbitrary files and directories on the server.
References
Link Resource
http://www.securityfocus.com/bid/95073 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-357-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fidelex:fx-2030a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fidelex:fx-2030a_controller:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:fidelex:fx-2030a-basic_firmware:11.50.18:*:*:*:*:*:*:*
cpe:2.3:h:fidelex:fx-2030a-basic_controller:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-13 21:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-9364

Mitre link : CVE-2016-9364

CVE.ORG link : CVE-2016-9364


JSON object : View

Products Affected

fidelex

  • fx-2030a-basic_controller
  • fx-2030a-basic_firmware
  • fx-2030a_controller
  • fx-2030a_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')