ZeroHour

CVE-2023-0956

CVSS 3.1
7.5 high
EPSS
1%p61
Published
()
Modified
Description

External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.

Vendors
tel-ster
Products
telwin scada webinterface
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.