PT-2023-32621 · Microsoft+1 · Internet Information Services+2

Published

2023-11-30

·

Updated

2023-12-11

·

CVE-2023-6352

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aquaforest TIFF Server (affected versions not specified)
Description The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-6352

Affected Products

Aquaforest Tiff Server
Internet Information Services
Windows