CVE-2019-18253

EUVD-2019-8051
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
hitachienergyrelion_670_firmware
𝑥
< 1p1r26
hitachienergyrelion_670_firmware
1.2 ≤
𝑥
< 1.2.3.17
hitachienergyrelion_670_firmware
2.0 ≤
𝑥
< 2.0.0.10
hitachienergyrelion_670_firmware
2.1 ≤
𝑥
< 2.1.0.1
𝑥
= Vulnerable software versions