PT-2019-19360 · Saet Impianti Speciali · Saet Impianti Speciali Tebe Small
Published
2019-05-31
·
Updated
2019-06-03
·
CVE-2019-9106
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAET Impianti Speciali TEBE Small version 05.01 build 1137
Description
The issue allows remote attackers to execute or include local .php files. This can be demonstrated by accessing the
/menu=php://filter/convert.base64-encode/resource=index.php endpoint to read index.php.Recommendations
For SAET Impianti Speciali TEBE Small version 05.01 build 1137, consider restricting access to the
menu parameter in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saet Impianti Speciali Tebe Small