vendor:
UPS Network Management Card
by:
Víctor García
6.1
CVSS
HIGH
Path Traversal
22
CWE
Product Name: UPS Network Management Card
Affected Version From: 4
Affected Version To: 4
Patch Exists: NO
Related CWE:
CPE: h:apc:ups_network_management_card:4
Platforms Tested: Kali Linux
2023
UPS Network Management Card 4 – Path Traversal
The exploit allows an attacker to traverse the directory structure and read sensitive files such as /etc/passwd on UPS Network Management Card 4 without authentication.
Mitigation:
To mitigate this vulnerability, restrict access to the affected system and ensure that sensitive directories are not directly accessible via the web.