PT-2023-27962 · Frauscher Sensortechnik Gmbh · Fds101
Published
2023-09-20
·
Updated
2023-09-23
·
CVE-2023-4152
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi versions 1.4.24 and all previous versions
Description
The issue allows a remote attacker to read all files on the filesystem of the FDS101 device by exploiting a path traversal vulnerability of the web interface using a crafted URL without authentication.
Recommendations
For versions 1.4.24 and all previous versions, consider disabling access to the web interface until a patch is available. Restrict access to the filesystem to minimize the risk of exploitation. Avoid using crafted URLs that could trigger the path traversal vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fds101