CVE-2012-4027: Path Traversal
Published Jul 16, 2012
·Updated
Directory traversal vulnerability in Tridium Niagara AX Framework allows remote attackers to read files outside of the intended images, nav, and px folders by leveraging incorrect permissions, as demonstrated by reading the config.bog file.
Affected Software
1 affected component
Tridium Niagara AX
Event History
Jul 16, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4027?
CVE-2012-4027 has been assigned a medium severity rating due to its potential to expose sensitive files.
2
How do I fix CVE-2012-4027?
To fix CVE-2012-4027, adjust the permissions for the affected directories to prevent unauthorized access.
3
What types of files can be accessed through CVE-2012-4027?
CVE-2012-4027 allows attackers to read files such as config.bog outside the intended directories.
4
Who is affected by CVE-2012-4027?
CVE-2012-4027 affects users of the Tridium Niagara AX Framework software.
5
What causes CVE-2012-4027?
CVE-2012-4027 is caused by incorrect permissions that enable directory traversal vulnerabilities.