PT-2017-10069 · Interschalt · Interschalt Maritime Systems Vdr G4E
Maxim Rupp
·
Published
2017-02-13
·
Updated
2021-06-22
·
CVE-2016-9339
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
INTERSCHALT Maritime Systems VDR G4e versions 5.220 and prior
Description
The issue allows an attacker to read files on the system due to a Path Traversal vulnerability. This occurs because external input is used to construct paths to files and directories without properly neutralizing special elements within the pathname.
Recommendations
For versions 5.220 and prior, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using external input to construct paths to files and directories until the issue is resolved.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Interschalt Maritime Systems Vdr G4E