Honeywell Experion PKS CVE-2014-9186 Remote File Include Vulnerability
BID:71753
Info
Honeywell Experion PKS CVE-2014-9186 Remote File Include Vulnerability
| Bugtraq ID: | 71753 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9186 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2014 12:00AM |
| Updated: | Dec 19 2014 12:00AM |
| Credit: | Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov of the Positive Technologies Research Team and Security Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Honeywell Experion PKS CVE-2014-9186 Remote File Include Vulnerability
Honeywell Experion PKS is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary script code in the context of the web server process.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2
Honeywell Experion PKS is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information or to execute arbitrary script code in the context of the web server process.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2
Exploit / POC
Honeywell Experion PKS CVE-2014-9186 Remote File Include Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Honeywell Experion PKS CVE-2014-9186 Remote File Include Vulnerability
References:
References: