CVE-2018-16059
endress wirelesshart_fieldgate_swg70_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-16059 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wirelesshart_fieldgate_swg70_firmwareBrowse endress / wirelesshart_fieldgate_swg70_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWirelessHART Fieldgate SWG70 3.0 - Directory TraversalExploitDB exploitby Hamit CİBONot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWirelessHART Fieldgate SWG70 3.0 - Local File InclusionCVSS 5.3
WirelessHART Fieldgate SWG70 3.0 is vulnerable to local file inclusion via the fcgi-bin/wgsetcgi filename parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the system, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in WirelessHART Fieldgate SWG70 3.0.
Source: ProjectDiscovery