PT-2023-6264 · Unknown · Cp-8031 Master Module+1

Published

2023-10-10

·

Updated

2023-10-16

·

CVE-2023-42796

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CP-8031 MASTER MODULE versions prior to CPCI85 V05.11 CP-8050 MASTER MODULE versions prior to CPCI85 V05.11
Description A vulnerability has been identified in the web server of the affected devices, which fails to properly sanitize user input for the "/sicweb-ajax/tmproot/" endpoint. This could allow an authenticated remote attacker to traverse directories on the system and download arbitrary files. The vulnerability could potentially be leveraged to escalate privileges to the administrator role by exploring active session IDs.
Recommendations For CP-8031 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue. For CP-8050 MASTER MODULE versions prior to CPCI85 V05.11, update to version CPCI85 V05.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/sicweb-ajax/tmproot/" endpoint until a patch is available.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06973
CVE-2023-42796

Affected Products

Cp-8031 Master Module
Cp-8050 Master Module