PT-2023-20485 · Telindus · Telindus Apsal

Alexis Pain

·

Published

2023-04-25

·

Updated

2023-05-04

·

CVE-2023-26098

CVSS v3.1

8.2

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:L/S:C/UI:R
Name of the Vulnerable Software and Affected Versions Telindus Apsal version 3.14.2022.235 b
Description An issue was discovered in the Open Document feature, allowing an attacker to upload a crafted file and execute arbitrary code.
Recommendations For Telindus Apsal version 3.14.2022.235 b, consider disabling the Open Document feature until a patch is available to prevent the execution of arbitrary code by an attacker.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-26098

Affected Products

Telindus Apsal