vendor:
pCOWeb HVAC BACnet Gateway
by:
LiquidWorm
8.8
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: pCOWeb HVAC BACnet Gateway
Affected Version From: Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A, Software version: v16 13020200
Affected Version To: Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A, Software version: v16 13020200
Patch Exists: YES
Related CWE:
CPE: cpe:a:carel_industries:pcoweb_hvac_bacnet_gateway:2.1.0
Platforms Tested:
2020
Carel pCOWeb HVAC BACnet Gateway 2.1.0 – Directory Traversal
The device suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
Mitigation:
Upgrade to the latest version of the firmware and application software.