ZDI-CAN-20536: ZDI-23-1030: (Pwn2Own) Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability
This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20536?
The severity of ZDI-CAN-20536 is considered high due to its ability to allow remote attackers to upload arbitrary files.
How do I fix ZDI-CAN-20536?
To fix ZDI-CAN-20536, ensure that you update your Triangle MicroWorks SCADA Data Gateway to the latest version that addresses this vulnerability.
What is the impact of ZDI-CAN-20536?
The impact of ZDI-CAN-20536 includes potential unauthorized access and control over the affected system, leading to further exploitation.
Is authentication enough to protect against ZDI-CAN-20536?
No, the authentication mechanism can be bypassed, so additional security measures must be implemented.
Who is affected by ZDI-CAN-20536?
All installations of Triangle MicroWorks SCADA Data Gateway that have not applied the necessary patches are affected by ZDI-CAN-20536.