Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
Lawo AG vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated Path Traversal

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

CWE-32Oct 24, 20241 related artifact
CVSS7.5v3.1EPSS4.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX