PT-2023-9113 · Telit · Telit Cinterion Ehs5/6/8+3
Alexander Kozlov
+1
·
Published
2023-11-08
·
Updated
2023-11-16
·
CVE-2023-47613
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Telit Cinterion BGS5
Telit Cinterion EHS5/6/8
Telit Cinterion PDS5/6/8
Telit Cinterion ELS61/81
Telit Cinterion PLS62
Description
A Relative Path Traversal issue exists that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system. This vulnerability is related to a software issue in the Telit Cinterion modems, which can be exploited to gain read and write access to arbitrary system files.
Recommendations
For Telit Cinterion BGS5, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
For Telit Cinterion EHS5/6/8, restrict access to protected files on the system until a patch is available.
For Telit Cinterion PDS5/6/8, avoid using vulnerable functions that allow file access until the issue is resolved.
For Telit Cinterion ELS61/81, consider disabling access to virtual directories to prevent attackers from escaping and accessing protected files.
For Telit Cinterion PLS62, restrict access to the system's file system to prevent read and write access to arbitrary files.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62