An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.
References
Configurations
History
21 Nov 2024, 05:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/158556/INNEO-Startup-TOOLS-2018-M040-13.0.70.3804-Remote-Code-Execution.html - Exploit, Third Party Advisory | |
References | () https://www.inneo.co.uk/en/product-development/inneo-in-house-products/startup-tools.html - Product, Vendor Advisory | |
References | () https://www.inneo.de/files/content/Produktentwicklung/Tools-und-Erweiterungen/Startup-TOOLS/INNEO-SA-SUT-2020-01.pdf - Vendor Advisory | |
References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-028.txt - Exploit, Third Party Advisory | |
References | () https://www.syss.de/pentest-blog/2020/syss-2020-028-sicherheitsschwachstelle-in-inneo-startup-tools-2017-und-2018/ - Third Party Advisory |
Information
Published : 2020-07-23 20:15
Updated : 2024-11-21 05:05
NVD link : CVE-2020-15492
Mitre link : CVE-2020-15492
CVE.ORG link : CVE-2020-15492
JSON object : View
Products Affected
inneo
- startup_tools
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')