CVE-2023-0956

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*

History

08 Aug 2023, 20:10

Type Values Removed Values Added
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03 - Third Party Advisory, US Government Resource
References (MISC) https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - (MISC) https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 - Vendor Advisory
References (MISC) https://cert.pl/posts/2023/07/CVE-2023-0956/ - (MISC) https://cert.pl/posts/2023/07/CVE-2023-0956/ - Third Party Advisory
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Tel-ster
Tel-ster telwin Scada Webinterface
CPE cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*

03 Aug 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 19:15

Updated : 2023-08-08 20:10


NVD link : CVE-2023-0956

Mitre link : CVE-2023-0956


JSON object : View

Products Affected

tel-ster

  • telwin_scada_webinterface
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')