PT-2023-5229 · Schweitzer Engineering Laboratories · Acselerator Bay Screen Builder

·

CVE-2023-31167

·

Publicado

2023-08-31

·

Atualizado

2023-09-07

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder Software versions prior to 1.0.49152.778
Description The issue is related to an improper limitation of a pathname to a restricted directory, allowing relative path traversal. This can potentially enable a remote attacker to access confidential information. The software is distributed by SEL-5033 SEL acSELerator RTAC, SEL-5030 Quickset, and SEL Compass.
Recommendations For versions prior to 1.0.49152.778, update to the acSELerator Bay Screen Builder release available on 20230602 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories and files to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05837
CVE-2023-31167

Produtos afetados

Acselerator Bay Screen Builder