There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.generex.de/support/changelogs/cs141/2-12 | Vendor Advisory | 
| https://www.generex.de/support/changelogs/cs141/page:2 | Vendor Advisory | 
| https://www.incibe-cert.es/en/early-warning/ics-advisories/update-03032023-multiple-vulnerabilities-generex-ups-cs141 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2023-03-31 22:15
Updated : 2023-04-06 19:46
NVD link : CVE-2022-47188
Mitre link : CVE-2022-47188
CVE.ORG link : CVE-2022-47188
JSON object : View
Products Affected
                generex
- cs141_firmware
 - cs141
 
