Vulnerability CVE-2023-27409


Published: 2023-05-09

Description:
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://cert-portal.siemens.com/productcert/pdf/ssa-325383.pdf

Copyright 2024, cxsecurity.com

 

Back to Top