PT-2024-19189 · Elspec · Elspec G5 Digital Fault Recorder

Benedikt Kühne

+1

·

Published

2024-03-19

·

Updated

2024-08-05

·

CVE-2024-22079

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elspec G5 digital fault recorder versions 1.1.4.15 and before
Description An issue was discovered in the system logs download mechanism, allowing directory traversal to occur. This could potentially expose system logs. If local network access exists, it is recommended to take immediate action to prevent data breaches.
Recommendations For versions 1.1.4.15 and before, update immediately and restrict log access to minimize the risk of exploitation. As a temporary workaround, consider restricting access to the system logs download mechanism until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-22079

Affected Products

Elspec G5 Digital Fault Recorder