IM
IronMonkey Threat Research

CVE-2020-7529 MEDIUM

Published: 2020-09-16 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.

Additional Descriptions (1)

Se presenta una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta a un Directorio Restringido ("Path Transversal") CWE-22, en SCADAPack 7x Remote Connect (versiones V3.6.3.574 y anteriores) que permite a un atacante colocar contenido en cualquier carpeta desprotegida del sistema de destino usando un archivo .RCZ diseñado

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22

Affected Products

Vendor Product Version Update Type
schneider-electric scadapack_7x_remote_connect * <built-in method update of dict object at 0x7e60e8c7e3c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:scadapack_7x_remote_connect:*:*:*:*:*:*:*:*

References

Notification
Message here