CVE-2024-27575

INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as with the /cgi-bin/display?file=/etc/passwd URI.
Configurations

No configuration.

History

21 Nov 2024, 09:04

Type Values Removed Values Added
References () https://gist.github.com/s4fv4n/098bd368bf054d008078e369108c2ebd - () https://gist.github.com/s4fv4n/098bd368bf054d008078e369108c2ebd -
References () https://www.inotec-licht.de/ - () https://www.inotec-licht.de/ -

03 Jul 2024, 01:50

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Apr 2024, 04:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Directory Traversal en INOTEC Sicherheitstechnik GmbH INOTEC Sicherheitstechnik GmbH WebServer CPS220/64 V.3.3.19 permite a un atacante remoto ejecutar código arbitrario a través del archivo /etc/passwd.
Summary (en) Directory Traversal vulnerability in INOTEC Sicherheitstechnik GmbH INOTEC Sicherheitstechnik GmbH WebServer CPS220/64 V.3.3.19 allows a remote attacker to execute arbitrary code via the /etc/passwd file. (en) INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as with the /cgi-bin/display?file=/etc/passwd URI.

04 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-04 13:15

Updated : 2024-11-21 09:04


NVD link : CVE-2024-27575

Mitre link : CVE-2024-27575

CVE.ORG link : CVE-2024-27575


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')