ZDI-CAN-20535: ZDI-23-1029: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability
This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20535?
The severity of ZDI-CAN-20535 is high due to its ability to allow remote attackers to write arbitrary files.
How do I fix ZDI-CAN-20535?
To fix ZDI-CAN-20535, apply the latest security patch provided by Triangle MicroWorks for the SCADA Data Gateway.
What are the consequences of exploiting ZDI-CAN-20535?
Exploiting ZDI-CAN-20535 can lead to unauthorized file modifications and potential system compromise.
What versions of Triangle MicroWorks SCADA Data Gateway are affected by ZDI-CAN-20535?
ZDI-CAN-20535 affects multiple versions of Triangle MicroWorks SCADA Data Gateway with the vulnerable authentication mechanism.
Is authentication required to exploit ZDI-CAN-20535?
Yes, authentication is required to exploit ZDI-CAN-20535, but the authentication mechanism can be bypassed.