CVE-2023-47613
09.11.2023, 07:15
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.
Vendor | Product | Version |
---|---|---|
telit | bgs5_firmware | - |
telit | ehs5_firmware | - |
telit | ehs6_firmware | - |
telit | ehs8_firmware | - |
telit | pds5_firmware | - |
telit | pds6_firmware | - |
telit | pds8_firmware | - |
telit | els61_firmware | - |
telit | els81_firmware | - |
telit | pls62_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-23 - Relative Path TraversalThe software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.