PT-2023-1983 · Roxy-Wi · Roxy-Wi

Sim4N6

·

Publicado

2023-03-13

·

Atualizado

2023-03-22

·

CVE-2023-25802

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 6.3.6.0
Description The issue is related to the Roxy-WI web interface for managing servers, which fails to correctly neutralize dir/../filename sequences. This allows an actor to gain information about a server. For example, sequences like /etc/nginx/../passwd can be used to access sensitive information. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to 6.3.6.0, update to version 6.3.6.0, which includes a patch for this issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using sequences like dir/../filename in the affected web interface until the issue is resolved.

Exploit

Correção

Exposure of Resource to Wrong Sphere

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01606
CVE-2023-25802
GHSA-QCMP-Q5H3-784M

Produtos afetados

Roxy-Wi