vendor:
WirelessHART Fieldgate SWG70
by:
Hamit CİBO
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: WirelessHART Fieldgate SWG70
Affected Version From: SWG70 3.X
Affected Version To: SWG70 3.X
Patch Exists: NO
Related CWE: N/A
CPE: a:endress:wirelesshart_fieldgate_swg70
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
WirelessHART Fieldgate SWG70 3.0 – Directory Traversal
A directory traversal vulnerability exists in WirelessHART Fieldgate SWG70 3.0. An attacker can send a specially crafted HTTP POST request to the vulnerable server to traverse the directory and read arbitrary files on the server.
Mitigation:
Ensure that user input is validated and sanitized before being used in file operations.