PT-2024-1445 · Unknown · Rapid Scada
Noam Moshe
·
Published
2024-01-11
·
Updated
2024-02-07
·
CVE-2024-22096
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid SCADA versions prior to 5.8.4
Description
The issue is related to errors in handling relative path to directory, allowing an attacker to read arbitrary files from the system by appending path traversal characters to the filename when using a specific command. This can be achieved by sending a specially crafted HTTP request.
Recommendations
For versions prior to 5.8.4, update to version 5.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the specific command that allows path traversal characters to be appended to the filename.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rapid Scada