PT-2022-11295 · Unknown · Ind780 Advanced Weighing Terminals
Published
2022-10-31
·
Updated
2022-11-02
·
CVE-2021-40661
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IND780 Advanced Weighing Terminals versions 7.2.10 through 8.0.07
Description
A remote, unauthenticated, directory traversal issue was identified within the web interface. It allows traversing the folders of the affected host by providing a traversal path to the
webpage parameter in AutoCE.ini. This could enable a remote unauthenticated adversary to access additional files on the affected system and perform further enumeration to identify system versions, potentially leading to further attacks.Recommendations
For versions 7.2.10 through 8.0.07, consider restricting access to the
webpage parameter in AutoCE.ini to minimize the risk of exploitation. As a temporary workaround, limit the ability to traverse folders through the web interface until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ind780 Advanced Weighing Terminals