ZDI-23-1029: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability
This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1029?
The vulnerability ZDI-23-1029 is classified as critical due to its ability for remote attackers to write arbitrary files.
How do I fix ZDI-23-1029?
To mitigate ZDI-23-1029, update to the latest version of Triangle MicroWorks SCADA Data Gateway following the vendor's security guidance.
What is the impact of ZDI-23-1029?
The impact of ZDI-23-1029 includes unauthorized file access and potential system compromise due to bypassing authentication.
Who is affected by ZDI-23-1029?
All installations of Triangle MicroWorks SCADA Data Gateway that have not implemented the latest security patches are affected by ZDI-23-1029.
Is authentication needed to exploit ZDI-23-1029?
Yes, authentication is required to exploit ZDI-23-1029, but the authentication mechanism can be bypassed.