Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
References
Link | Resource |
---|---|
http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9 | Vendor Advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03 | Third Party Advisory US Government Resource |
http://zerodayinitiative.com/advisories/ZDI-15-439/ |
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-09-18 15:59
Updated : 2015-09-23 11:53
NVD link : CVE-2015-6459
Mitre link : CVE-2015-6459
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
ge
- mds_pulsenet