PT-2023-24013 · Symcon · Ip-Symcon

·

CVE-2023-32767

·

Published

2023-05-17

·

Updated

2025-01-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Symcon IP-Symcon versions prior to 6.3
Description The web interface of Symcon IP-Symcon allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL. This issue enables unauthorized access to sensitive information.
Recommendations For versions prior to 6.3, update to version 6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-32767

Affected Products

Ip-Symcon