CVE-2023-0956
Summary
| CVE | CVE-2023-0956 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-03 19:15:00 UTC |
| Updated | 2023-08-08 20:10:00 UTC |
| Description | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tel-ster | Telwin Scada Webinterface | All | All | All | All |
| Application | Tel-ster | Telwin Scada Webinterface | 8.0 | All | All | All |
| Application | Tel-ster | Telwin Scada Webinterface | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nie znaleziono strony | CERT Polska | MISC | cert.pl | |
| TEL-STER Sp. z o.o. | System SCADA | Oprogramowanie | Automatyka | Wizualizacja | Nominacje - Ważne! Krytyczna podatność TelWin SCADA WebInterface [CVE-2023-0956] | MISC | www.tel-ster.pl | |
| TEL-STER TelWin SCADA WebInterface | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.