First published: Wed Nov 15 2023(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Galaxy Vl Firmware | =12.21 | |
Schneider-electric Galaxy Vl | ||
All of | ||
Schneider-electric Galaxy Vs Firmware | =6.82 | |
Schneider-electric Galaxy Vs |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6032 is a Path Traversal vulnerability that allows an attacker to access files outside of the restricted directory.
CVE-2023-6032 has a severity rating of medium (5.3).
Schneider-electric Galaxy Vl Firmware version 12.21 and Schneider-electric Galaxy Vs Firmware version 6.82 are affected.
CVE-2023-6032 allows an attacker to navigate to the Network Management Card via HTTPS and perform file system enumeration and file download by exploiting the Path Traversal vulnerability.
To fix CVE-2023-6032, apply the latest firmware update provided by Schneider-electric for Galaxy Vl Firmware version 12.21 and Galaxy Vs Firmware version 6.82.