PT-2023-6264 · Unknown · Cp-8031 Master Module+1
Published
2023-10-10
·
Updated
2023-10-16
·
CVE-2023-42796
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CP-8031 MASTER MODULE versions prior to CPCI85 V05.11
CP-8050 MASTER MODULE versions prior to CPCI85 V05.11
Description
A vulnerability has been identified in the web server of the affected devices, which fails to properly sanitize user input for the "/sicweb-ajax/tmproot/" endpoint. This could allow an authenticated remote attacker to traverse directories on the system and download arbitrary files. The vulnerability could potentially be leveraged to escalate privileges to the administrator role by exploring active session IDs.
Recommendations
For CP-8031 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue.
For CP-8050 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/sicweb-ajax/tmproot/" endpoint until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-8031 Master Module
Cp-8050 Master Module