QID 591347
Date Published: 2023-02-17
QID 591347: Black Box KVM Path Traversal Vulnerability (ICSA-23-010-01)
AFFECTED PRODUCTS
Black Box KVM ACR1000A-R-R2: Firmware version v3.4.31307
Black Box KVM ACR1000A-T-R2: Firmware version v3.4.31307
Black Box KVM ACR1002A-T: Firmware version v3.4.31307
Black Box KVM ACR1002A-R: Firmware version v3.4.31307
Black Box KVM ACR1020A-T: Firmware version v3.4.31307
QID Detection Logic:
This QID checks for the Vulnerable version of Black Box KVM using passive scanning.
Successful exploitation of this vulnerability could allow an attacker to read sensitive data on the built-in web servers of the affected devices.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-23-010-01 for affected packages and patching details.
Vendor References
- icsa-23-010-01 -
www.cisa.gov/uscert/ics/advisories/icsa-23-010-01
CVEs related to QID 591347
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-23-010-01 |
|