A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
2023-11-15T04:15:19.890
2024-11-21T08:43:00.760
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | galaxy_vl_firmware | 12.21 | Yes |
Hardware | schneider-electric | galaxy_vl | - | No |
Operating System | schneider-electric | galaxy_vs_firmware | 6.82 | Yes |
Hardware | schneider-electric | galaxy_vs | - | No |