CVE-2018-16059
MEDIUM EXPLOITED NUCLEIEndress+Hauser WirelessHART Fieldgate SWG70 3.x - Path Traversal via fcgi-bin/wgsetcgi filename Parameter
Title source: llmExploitation Summary
CVE-2018-16059 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Hamit CİBO. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in WirelessHART Fieldgate SWG70 3.0, allowing an attacker to read arbitrary files (e.g., /etc/passwd) via a crafted POST request to the /fcgi-bin/wgsetcgi endpoint.
Description
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in WirelessHART Fieldgate SWG70 3.0, allowing an attacker to read arbitrary files (e.g., /etc/passwd) via a crafted POST request to the /fcgi-bin/wgsetcgi endpoint.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N