VulnerabilityModified
CVE-2020-11420
UPS Adapter CS141 before 1.90 allows Directory Traversal.
MEDIUM 6.5EPSS 1.64%
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- abb/cs141 firmware · generex/cs141 firmware
- Source
- cve@mitre.org
References
- https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdfVendor Advisory
- https://www.generex.de/index.php?option=com_content&task=view&id=185&Itemid=249Release Notes, Vendor Advisory
- https://www.generex.de/support/changelogs/cs141/page:2Release Notes, Vendor Advisory
- https://library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdfVendor Advisory
- https://www.generex.de/index.php?option=com_content&task=view&id=185&Itemid=249Release Notes, Vendor Advisory
- https://www.generex.de/support/changelogs/cs141/page:2Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.