PT-2023-6264 · Unknown · Cp-8031 Master Module+1
Publicado
2023-10-10
·
Atualizado
2023-10-16
·
CVE-2023-42796
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CP-8031 MASTER MODULE versions prior to CPCI85 V05.11
CP-8050 MASTER MODULE versions prior to CPCI85 V05.11
Description
A vulnerability has been identified in the web server of the affected devices, which fails to properly sanitize user input for the "/sicweb-ajax/tmproot/" endpoint. This could allow an authenticated remote attacker to traverse directories on the system and download arbitrary files. The vulnerability could potentially be leveraged to escalate privileges to the administrator role by exploring active session IDs.
Recommendations
For CP-8031 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue.
For CP-8050 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/sicweb-ajax/tmproot/" endpoint until a patch is available.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cp-8031 Master Module
Cp-8050 Master Module