PT-2024-1445 · Unknown · Rapid Scada

Noam Moshe

·

Published

2024-01-11

·

Updated

2024-02-07

·

CVE-2024-22096

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rapid SCADA versions prior to 5.8.4
Description The issue is related to errors in handling relative path to directory, allowing an attacker to read arbitrary files from the system by appending path traversal characters to the filename when using a specific command. This can be achieved by sending a specially crafted HTTP request.
Recommendations For versions prior to 5.8.4, update to version 5.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the specific command that allows path traversal characters to be appended to the filename.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00930
CVE-2024-22096

Affected Products

Rapid Scada