ZeroHour

CVE-2017-20184

PoC
CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.

Vendors
gavazzionline
Products
powersoft
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.