CVE-2023-6118
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: iletisim@usom.gov.tr (Secondary)
Description
Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal.
This issue affects IP Camera: before b1130.1.0.1.
Affected (17)
Products: Neutron: Neu Ipb210 28 Firmware, Ntl Pt 06wod 3mp Firmware, Neu Ipb410 28 Firmware, Ntl Bc 01w Firmware, Neu Ipbm211 Firmware, Ntl Pt 09 Wos 3mp Firmware, Neu Ipbm411 Firmware, Ntl Pt 10 4gwos 3mp Firmware, Ipc2224 Sr3 Npf 36 Firmware, Ipc2624 Sr3 Npf 36 Firmware, Ntl Bc 03 Snm Firmware, Ntl Bc 03 Snp Firmware, Neu Ipd220 28 Firmware, Ntl Bc01 M Firmware, Neu Ipdm221 Firmware, Neu Ipdm421 Firmware, Ntl Ip05 3mp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipb210 28 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Pt 06wod 3mp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipb410 28 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Bc 01w | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipbm211 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Pt 09 Wos 3mp | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipbm411 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Pt 10 4gwos 3mp | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ipc2224 Sr3 Npf 36 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ipc2624 Sr3 Npf 36 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Bc 03 Snm | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Bc 03 Snp | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipd220 28 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Bc01 M | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipdm221 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Neu Ipdm421 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before b1130.1.0.1 |
| Running on/with | Platform Versions |
|---|---|
Neutron Ntl Ip05 3mp | All versions |
Related CWEs
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-25
Path Traversal: '/../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.
References (3)
Source: iletisim@usom.gov.tr
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.