PT-2023-4580 · Iagona · Iagona Scrutisweb
Jorian Van Den Hout
+2
·
Published
2023-07-18
·
Updated
2023-08-16
·
CVE-2023-33871
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Iagona ScrutisWeb versions 2.1.37 and prior
Description
The issue exists due to incorrect restriction of the path name to a directory with limited access. Exploitation of this issue may allow a remote attacker to gain direct access to any arbitrary file outside the webroot. Researchers found several flaws in the ScrutisWeb ATM fleet monitoring software that can expose ATMs to hacking.
Recommendations
For Iagona ScrutisWeb versions 2.1.37 and prior, update to a version later than 2.1.37 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories outside the webroot to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iagona Scrutisweb