Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
BID:107416
CVE-2018-16059 |Info
Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
| Bugtraq ID: | 107416 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-16059 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2019 12:00AM |
| Updated: | Mar 14 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Pepperl+Fuchs WHA-GW-F2D2-0-AS-Z2-ETH.EIP 0 Pepperl+Fuchs WHA-GW-F2D2-0-AS-Z2-ETH 0 |
| Not Vulnerable: |
Pepperl+Fuchs WHA-GW-F2D2-0-AS-Z2-ETH.EIP 02.00.01 Pepperl+Fuchs WHA-GW-F2D2-0-AS-Z2-ETH 03.00.08 |
Discussion
Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
Multiple PEPPERL+FUCHS products are prone to a directory-traversal vulnerability.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to retrieve sensitive information. This may aid in further attacks.
The following products and versions are affected:
WirelessHART Gateway WHA-GW-F2D2-0-AS-Z2-ETH 03.00.08
WirelessHART Gateway WHA-GW-F2D2-0-AS-Z2-ETH.EIP 02.00.01
Multiple PEPPERL+FUCHS products are prone to a directory-traversal vulnerability.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to retrieve sensitive information. This may aid in further attacks.
The following products and versions are affected:
WirelessHART Gateway WHA-GW-F2D2-0-AS-Z2-ETH 03.00.08
WirelessHART Gateway WHA-GW-F2D2-0-AS-Z2-ETH.EIP 02.00.01
Exploit / POC
Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple PEPPERL+FUCHS Products CVE-2018-16059 Directory Traversal Vulnerability
References:
References:
- PEPPERL+FUCHS Homepage (PEPPERL+FUCHS)
- ICSA-19-073-03 PEPPERL+FUCHS WirelessHART-Gateways (CERT)