CVE-2023-6407: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6407?
CVE-2023-6407 is considered a high-severity vulnerability due to its potential for arbitrary file deletion by low-privileged attackers.
How do I fix CVE-2023-6407?
To mitigate CVE-2023-6407, it's recommended to update the Schneider Electric Easy UPS Online Monitoring Software to a version higher than 2.6-ga-01-23248.
Who is affected by CVE-2023-6407?
CVE-2023-6407 affects Schneider Electric's Easy UPS Online Monitoring Software running on various versions of Windows 10 and Windows Server.
What type of vulnerability is CVE-2023-6407?
CVE-2023-6407 is classified as a CWE-22 vulnerability, specifically related to path traversal and improper limitations on file access.
Can CVE-2023-6407 be exploited remotely?
No, CVE-2023-6407 requires local access by a low-privileged attacker to exploit the vulnerability.