vendor:
SOC FL9600 FastLine
by:
Mike Jankowski-Lorek, Marcin Kozlowski / Cqure
6.1
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: SOC FL9600 FastLine
Affected Version From: V06
Affected Version To: V06
Patch Exists: NO
Related CWE: CVE-2023-37607
CPE: a:automatic-systems:soc_fl9600_fastline:V06
Platforms Tested:
2023
Directory Traversal in Automatic-Systems SOC FL9600 FastLine
The Automatic-Systems SOC FL9600 FastLine V06 allows Directory Traversal via a specially crafted HTTP request. An attacker can exploit this vulnerability to read arbitrary files on the server, such as sensitive system files like 'passwd'. This vulnerability has been assigned CVE-2023-37607.
Mitigation:
To mitigate this vulnerability, restrict user input and validate file paths to prevent directory traversal attacks. Additionally, avoid exposing sensitive system files to the web server.