VulnerabilityModified
CVE-2016-9339
External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.
MEDIUM 5.3EPSS 1.71%
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- macgregor/interschalt vdr g4e firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/94776Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94776Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.