CVE-2015-0984: Path Traversal
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0984?
CVE-2015-0984 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2015-0984?
To fix CVE-2015-0984, upgrade the affected Honeywell Excel Web devices to version 2.04.01 or later.
What types of devices are affected by CVE-2015-0984?
CVE-2015-0984 affects various Honeywell Excel Web XL1000 controllers, including models with different I/O configurations.
What is the nature of the vulnerability in CVE-2015-0984?
CVE-2015-0984 is a directory traversal vulnerability in the FTP server that allows unauthorized access to restricted files.
Can CVE-2015-0984 be exploited remotely?
Yes, CVE-2015-0984 can be exploited remotely, allowing attackers to potentially gain unauthorized access to system files.