QID 591088
Date Published: 2022-10-11
QID 591088: ABB FOX515T Vulnerability (ABB-VU-PGGA-1KHW028693)
AFFECTED PRODUCTS
FOX515T release 1.0
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
The embedded web server deployed in the FOX515T device is vulnerable to Local File Inclusion (LFI) vulnerability. Under certain conditions the web server accepts a parameter that specifies a file for display or for use as a template. The filename provided to the script is not validated by the application, an attacker could retrieve any file on the server.
Solution
Customers are advised to refer to CERT MITIGATIONS section ABB-VU-PGGA-1KHW028693 for affected packages and patching details.
Vendor References
CVEs related to QID 591088
Software Advisories
| Advisory ID | Software | Component | Link |
|---|