PT-2023-1983 · Roxy-Wi · Roxy-Wi
Sim4N6
·
Publicado
2023-03-13
·
Atualizado
2023-03-22
·
CVE-2023-25802
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 6.3.6.0
Description
The issue is related to the Roxy-WI web interface for managing servers, which fails to correctly neutralize
dir/../filename sequences. This allows an actor to gain information about a server. For example, sequences like /etc/nginx/../passwd can be used to access sensitive information. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.Recommendations
For versions prior to 6.3.6.0, update to version 6.3.6.0, which includes a patch for this issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using sequences like
dir/../filename in the affected web interface until the issue is resolved.Exploit
Correção
Exposure of Resource to Wrong Sphere
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Roxy-Wi