The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL.
References
Link | Resource |
---|---|
https://community.symcon.de/t/ip-symcon-6-3-stable-changelog/40276/87 | Release Notes |
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-014.txt | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-17T00:00:00
Updated: 2023-05-17T00:00:00
Reserved: 2023-05-15T00:00:00
Link: CVE-2023-32767
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-05-17T20:15:10.757
Modified: 2023-05-25T17:27:17.517
Link: CVE-2023-32767
JSON object: View
Redhat Information
No data.
CWE