PT-2011-1681 · Serial Ethernet Server+4 · Serial Ethernet Server+4

Michael Orlando

·

Published

2011-02-14

·

Updated

2011-02-15

·

CVE-2010-4731

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions WebSCADA WS100 and WS200 versions (affected versions not specified) Easy Connect EC150 versions (affected versions not specified) Modbus RTU - TCP Gateway MB100 versions (affected versions not specified) Serial Ethernet Server SS100 versions (affected versions not specified) IntelliCom NetBiter NB100 and NB200 platforms versions (affected versions not specified)
Description The issue allows remote authenticated administrators to read arbitrary files via a full pathname in the file parameter. This is a result of an absolute path traversal vulnerability in cgi-bin/read.cgi.
Recommendations For WebSCADA WS100 and WS200, restrict access to the cgi-bin/read.cgi endpoint to minimize the risk of exploitation. For Easy Connect EC150, avoid using the file parameter in the affected API endpoint until the issue is resolved. For Modbus RTU - TCP Gateway MB100, consider disabling the read.cgi function until a patch is available. For Serial Ethernet Server SS100, restrict access to the vulnerable cgi-bin module to minimize the risk of exploitation. For IntelliCom NetBiter NB100 and NB200 platforms, as a temporary workaround, consider limiting the privileges of authenticated administrators to reduce the impact of the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4731

Affected Products

Easy Connect
Intellicom Netbiter
Modbus Rtu - Tcp Gateway
Serial Ethernet Server
Webscada