CVE-2024-41973Path Traversal: '.../...//' in Cc100 0751-9x01

Severity
8.1HIGHNVD
EPSS
1.8%
top 17.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18

Description

A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages12 packages

CVEListV5wago/cc100_0751-9x010.0.04.5.10 (FW27)
CVEListV5wago/cc100_0751_9x010.0.004.03.03 (72)+1
CVEListV5wago/tp600_0762-420x_8000-000x0.0.04.5.10 (FW27)
CVEListV5wago/tp600_0762-430x_8000-000x0.0.04.5.10 (FW27)
CVEListV5wago/tp600_0762-520x_8000-000x0.0.04.5.10 (FW27)

🔴Vulnerability Details

2
GHSA
GHSA-jw5r-wxx3-rm98: A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges2024-11-18
CVEList
WAGO: Remote Arbitrary File Write with Root Privileges in multiple Devices2024-11-18
CVE-2024-41973 — Path Traversal: '.../...//' | cvebase