CVE-2023-6407
published 2023-12-14CVE-2023-6407: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon…
PriorityP433high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.24%
14.8th percentile
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by
a local and low-privileged attacker.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | easy_ups_online_monitoring_software | < 2.6-ga-01-23248 | 2.6-ga-01-23248 |
| schneider_electric | easy_ups_online_monitoring_software | — | — |
| x.org | libx11 | >= 0 < 2:1.6.2-1ubuntu2.1+esm5 | 2:1.6.2-1ubuntu2.1+esm5 |
| x.org | libx11 | >= 0 < 2:1.6.3-1ubuntu2.2+esm4 | 2:1.6.3-1ubuntu2.2+esm4 |
| x.org | libx11 | >= 0 < 2:1.6.4-3ubuntu0.4+esm2 | 2:1.6.4-3ubuntu0.4+esm2 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Easy UPS Online Monitoring Software
cisa_ics·2023-12-12·CVSS 5.3
[MEDIUM] Schneider Electric Easy UPS Online Monitoring Software
ICS Advisory
##
Schneider Electric Easy UPS Online Monitoring Software
Release DateDecember 12, 2023
Alert CodeICSA-23-346-01
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.3
- ATTENTION:
- Vendor: Schneider Electric
- Equipment: Easy UPS Online Monitoring Software
- Vulnerability: Path Traversal
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow elevation of privileges which could result in arbitrary file deletion with system privileges.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports that the following versions of Easy UPS Online Monitoring Software are affected:
- Easy UPS Online Monitoring Software (Windows 10, 11, Windows
Server 2016, 2019, 2022): 2.6-GA-01-23116 and prior
## 3.2 Vulnerabil
GHSA
GHSA-94j2-x7q3-948j: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion
ghsa_unreviewed·2023-12-14
CVE-2023-6407 [MEDIUM] CWE-22 GHSA-94j2-x7q3-948j: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by
a local and low-privileged attacker.
OSV
libx11 vulnerabilities
osv·2023-10-10·CVSS 5.5
libx11 vulnerabilities
libx11 vulnerabilities
USN-6407-1 fixed several vulnerabilities in libx11. This update provides
the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Gregory James Duck discovered that libx11 incorrectly handled certain
keyboard symbols. If a user were tricked into connecting to a malicious X
server, a remote attacker could use this issue to cause libx11 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2023-43785)
Yair Mizrahi discovered that libx11 incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could possibly use this issue to consume
memory, leading to a denial of service. (CVE-2023-43786)
Yai
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-14
Published