First published: Fri Dec 31 2004(Updated: )
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InTouch | =1.31 | |
AVEVA InTouch | =1.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1795 is considered to be of low severity as it primarily allows local users to access the filesystem.
To fix CVE-2004-1795, you should apply any available updates for Info Touch Surfnet version 1.31 or implement access controls to restrict local user filesystem access.
CVE-2004-1795 affects users of Info Touch Surfnet version 1.31.
CVE-2004-1795 is a local file access vulnerability that can be exploited through the kiosk's 'file://' URI.
Yes, limiting local user access rights can serve as a temporary workaround for CVE-2004-1795 until a proper fix is applied.