PT-2015-6351 · Innologic · Ids Rtu 850C

Benjamin Kahler

+1

·

Published

2015-05-31

·

Updated

2016-12-06

·

CVE-2015-3939

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IDS RTU 850C devices (affected versions not specified)
Description A directory traversal issue exists in the NC854 and NC856 modules, allowing remote authenticated users to read arbitrary files. This is possible via unspecified vectors involving an internal web server. For example, it can be used to read a TELNET credentials file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3939

Affected Products

Ids Rtu 850C