CVE-2023-3512
Summary
| CVE | CVE-2023-3512 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-04 11:15:00 UTC |
| Updated | 2023-10-05 17:04:00 UTC |
| Description | Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file" parameter. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Setelsa-security | Conacwin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Relative path traversal vulnerability in Setelsa Security... · CVE-2023-3512 · GitHub Advisory Database · GitHub | MISC | github.com | Third Party Advisory |
| https/www.incibe.es/en/incibe-cert/notices/aviso/relative-path-trav... | MISC | https | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.