Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 117 bronnen 1 kritiek 3 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2015-0984

HIGH · 10.0 CVSS Gepubliceerd: CWE-22

Beschrijving

Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.

Vendors

Honeywell

Affected products

Excel Web Xl 1000c100 104 I/o Excel Web Xl 1000c1000 600 I/o Excel Web Xl 1000c1000 600 I/o Uukl Excel Web Xl 1000c100u 104 I/o Uukl Excel Web Xl 1000c50 52 I/o Excel Web Xl 1000c500 300 I/o Excel Web Xl 1000c500 300 I/o Uukl Excel Web Xl 1000c50u 52 I/o Uukl

References