CVE-2023-0956

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-08-03 19:15

Updated : 2023-08-08 20:10


NVD link : CVE-2023-0956

Mitre link : CVE-2023-0956

CVE.ORG link : CVE-2023-0956


JSON object : View

Products Affected

tel-ster

  • telwin_scada_webinterface
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')