CVE-2023-0956

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:38

Type Values Removed Values Added
References () https://cert.pl/posts/2023/07/CVE-2023-0956/ - Third Party Advisory () https://cert.pl/posts/2023/07/CVE-2023-0956/ - Third Party Advisory
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - Third Party Advisory, US Government Resource
References () https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - Vendor Advisory () https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - Vendor Advisory

08 Aug 2023, 20:10

Type Values Removed Values Added
CWE CWE-22
CPE cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
First Time Tel-ster telwin Scada Webinterface
Tel-ster
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - Third Party Advisory, US Government Resource
References (MISC) https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - (MISC) https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - Vendor Advisory
References (MISC) https://cert.pl/posts/2023/07/CVE-2023-0956/ - (MISC) https://cert.pl/posts/2023/07/CVE-2023-0956/ - Third Party Advisory

03 Aug 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 19:15

Updated : 2024-11-21 07:38


NVD link : CVE-2023-0956

Mitre link : CVE-2023-0956

CVE.ORG link : CVE-2023-0956


JSON object : View

Products Affected

tel-ster

  • telwin_scada_webinterface
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')