First published: Fri Apr 01 2016(Updated: )
Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
ICONICS WebHMI | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2289 has been classified with a high severity due to its potential impact on confidentiality.
CVE-2016-2289 allows remote attackers to perform directory traversal, enabling them to access sensitive configuration files.
To mitigate CVE-2016-2289, upgrade your ICONICS WebHMI to a version later than 9.0.
Yes, CVE-2016-2289 can be exploited remotely by attackers to read configuration files.
The exploitation of CVE-2016-2289 may lead to the discovery of password hashes and other sensitive information.