PT-2023-9113 · Telit · Telit Cinterion Ehs5/6/8+3

Alexander Kozlov

+1

·

Published

2023-11-08

·

Updated

2023-11-16

·

CVE-2023-47613

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Telit Cinterion BGS5 Telit Cinterion EHS5/6/8 Telit Cinterion PDS5/6/8 Telit Cinterion ELS61/81 Telit Cinterion PLS62
Description A Relative Path Traversal issue exists that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system. This vulnerability is related to a software issue in the Telit Cinterion modems, which can be exploited to gain read and write access to arbitrary system files.
Recommendations For Telit Cinterion BGS5, consider restricting access to sensitive files and directories to minimize the risk of exploitation. For Telit Cinterion EHS5/6/8, restrict access to protected files on the system until a patch is available. For Telit Cinterion PDS5/6/8, avoid using vulnerable functions that allow file access until the issue is resolved. For Telit Cinterion ELS61/81, consider disabling access to virtual directories to prevent attackers from escaping and accessing protected files. For Telit Cinterion PLS62, restrict access to the system's file system to prevent read and write access to arbitrary files.

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2024-03899
CVE-2023-47613

Affected Products

Telit Cinterion Bgs5
Telit Cinterion Ehs5/6/8
Telit Cinterion Els61/81
Telit Cinterion Pls62