CVE-2016-2289: Path Traversal
Published Apr 1, 2016
·Updated
Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified vectors.
Affected Software
1 affected component
ICONICS WebHMI<=9.0
Event History
Apr 1, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2289?
CVE-2016-2289 has been classified with a high severity due to its potential impact on confidentiality.
2
How does CVE-2016-2289 affect ICONICS WebHMI?
CVE-2016-2289 allows remote attackers to perform directory traversal, enabling them to access sensitive configuration files.
3
How do I fix CVE-2016-2289?
To mitigate CVE-2016-2289, upgrade your ICONICS WebHMI to a version later than 9.0.
4
Can CVE-2016-2289 be exploited remotely?
Yes, CVE-2016-2289 can be exploited remotely by attackers to read configuration files.
5
What are the risks associated with CVE-2016-2289?
The exploitation of CVE-2016-2289 may lead to the discovery of password hashes and other sensitive information.