Record summary

CVE-2023-39026 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck1.10.8affected

Proofs of concept

1

Catalogued exploits

ExploitDBFileMage Gateway 1.10.9 - Local File InclusionExploitDB exploitby Bryce Raindayzz HartyNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHFileMage Gateway - Directory TraversalCVSS 7.5

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

Impact

An attacker can view, modify, or delete sensitive files on the system, potentially leading to unauthorized access, data leakage, or system compromise.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the directory traversal vulnerability in FileMage Gateway.

WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscve2023cvepacketstormlfifilemagemicrosoftvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Shodan: title:"FileMage"
Shodan: cpe:"cpe:2.3:o:microsoft:windows"

Source: ProjectDiscovery

References

4