PT-2024-19193 · Elspec · Elspec G5 Digital Fault Recorder

Benedikt Kühne

+1

·

Published

2024-03-19

·

Updated

2024-08-05

·

CVE-2024-22082

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Elspec G5 digital fault recorder versions 1.1.4.15 and before
Description An issue was discovered that allows unauthenticated directory listing to occur. The web interface can be abused by an attacker to gain a better understanding of the operating system.
Recommendations For Elspec G5 digital fault recorder versions 1.1.4.15 and before, consider restricting access to the web interface until a patch is available. As a temporary workaround, limit the information exposed through the web interface to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-22082

Affected Products

Elspec G5 Digital Fault Recorder