PT-2024-15776 · Byzoro · Byzoro Smart S150 Management Platform

Rollingchair

·

Published

2024-01-19

·

Updated

2024-10-21

·

CVE-2024-0716

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Byzoro Smart S150 Management Platform version V31R02B15
Description A vulnerability has been found in the Byzoro Smart S150 Management Platform, affecting an unknown part of the file /log/download.php of the component Backup File Handler. This leads to information disclosure and can be initiated remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations For version V31R02B15, as a temporary workaround, consider restricting access to the /log/download.php file until a patch is available. Additionally, restrict the use of the Backup File Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-0716

Affected Products

Byzoro Smart S150 Management Platform