PT-2015-6351 · Innologic · Ids Rtu 850C
Benjamin Kahler
+1
·
Published
2015-05-31
·
Updated
2016-12-06
·
CVE-2015-3939
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IDS RTU 850C devices (affected versions not specified)
Description
A directory traversal issue exists in the NC854 and NC856 modules, allowing remote authenticated users to read arbitrary files. This is possible via unspecified vectors involving an internal web server. For example, it can be used to read a TELNET credentials file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ids Rtu 850C