Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the handling of event logs. The issue results from improper sanitization of log output. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-20535.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new | Release Notes |
https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new | Release Notes |
https://www.zerodayinitiative.com/advisories/ZDI-23-1029/ | Third Party Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-23-1029/ | Third Party Advisory |
Configurations
History
17 Jun 2025, 21:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.trianglemicroworks.com/products/scada-data-gateway/what's-new - Release Notes | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-23-1029/ - Third Party Advisory | |
First Time |
Trianglemicroworks
Trianglemicroworks scada Data Gateway |
|
CPE | cpe:2.3:a:trianglemicroworks:scada_data_gateway:5.1.3.20324:*:*:*:*:*:*:* |
03 May 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-03 03:15
Updated : 2025-06-17 21:03
NVD link : CVE-2023-39461
Mitre link : CVE-2023-39461
JSON object : View
Products Affected
trianglemicroworks
- scada_data_gateway
CWE
No CWE.