SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11420

UPS Adapter CS141 before 1.90 allows Directory Traversal.

MEDIUM 6.5EPSS 1.64%

Does this matter?

Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.

Description

UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.64% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
abb/cs141 firmware · generex/cs141 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.