CVE-2024-10313

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-24 18:15

Updated : 2024-10-25 12:56


NVD link : CVE-2024-10313

Mitre link : CVE-2024-10313


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')