ZDI-23-1027: Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1027?
The severity of ZDI-23-1027 is categorized as a medium risk due to the requirement for user interaction to exploit the vulnerability.
How do I fix ZDI-23-1027?
To fix ZDI-23-1027, update the Triangle MicroWorks SCADA Data Gateway software to the latest version provided by the vendor.
What are the conditions required to exploit ZDI-23-1027?
Exploitation of ZDI-23-1027 requires the target user to visit a malicious webpage or open a malicious file.
What are the potential consequences of ZDI-23-1027?
The potential consequences of ZDI-23-1027 include remote attackers being able to create arbitrary files on affected installations.
Who is affected by ZDI-23-1027?
ZDI-23-1027 affects installations of Triangle MicroWorks SCADA Data Gateway.