IM
IronMonkey Threat Research

CVE-2023-6032 MEDIUM

Published: 2023-11-15 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.

Additional Descriptions (1)

Existe una vulnerabilidad CWE-22: Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ("Path Traversal") que podría causar una enumeración del sistema de archivos y una descarga de archivos cuando un atacante navega a la Tarjeta de Administración de Red a través de HTTPS.

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22

Affected Products

Vendor Product Version Update Type
schneider-electric galaxy_vl_firmware 12.21 <built-in method update of dict object at 0x7e61109d77c0> Operating System
schneider-electric galaxy_vs_firmware 6.82 <built-in method update of dict object at 0x7e60e884c7c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:galaxy_vl_firmware:12.21:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:galaxy_vl:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:galaxy_vs_firmware:6.82:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:galaxy_vs:-:*:*:*:*:*:*:*
Notification
Message here