SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9339

External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.

MEDIUM 5.3EPSS 1.71%

Does this matter?

Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.71% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
macgregor/interschalt vdr g4e firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.