CVE-2023-39459: Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of workspace files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of Administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39459?
CVE-2023-39459 is rated as high severity due to the potential for remote file creation without proper authentication.
How do I fix CVE-2023-39459?
To fix CVE-2023-39459, apply the latest security patches provided by Triangle MicroWorks for the SCADA Data Gateway.
What types of attacks are possible with CVE-2023-39459?
CVE-2023-39459 allows attackers to create arbitrary files on the affected installations, potentially leading to data breaches or system compromise.
Is user interaction necessary to exploit CVE-2023-39459?
Yes, user interaction is required for CVE-2023-39459 as the target must visit a malicious page or open a malicious file.
Which software versions are affected by CVE-2023-39459?
CVE-2023-39459 affects certain versions of the Triangle MicroWorks SCADA Data Gateway.