CVE-2020-11420
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.
Affected (2)
Products: Abb: Cs141 Firmware · Generex: Cs141 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.66 to 1.88 |
| Running on/with | Platform Versions |
|---|---|
Abb Cs141 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.90 |
| Running on/with | Platform Versions |
|---|---|
Generex Cs141 | All versions |
References (6)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.