Record summary

CVE-2023-40924 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 6.00affected

Proofs of concept

1

Repository PoCs

GitHubYobing1/CVE-2023-40924Repository PoCby Yobing1Stars: 1Not analyzed1 file

799 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHSolarView Compact < 6.00 - Directory TraversalCVSS 7.5

SolarView Compact before version 6.00 is vulnerable to directory traversal via the file parameter in downloader.php. An unauthenticated attacker can read arbitrary files from the system by using path traversal sequences with a null byte bypass to access sensitive files such as /etc/passwd.

Impact

An attacker can read sensitive system files including /etc/passwd which may contain password hashes on embedded devices, potentially leading to full system compromise.

Remediation

Upgrade SolarView Compact to version 6.00 or later.

WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscvecve2023lfisolarviewcontectraversalvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:contec:solarview_compact_firmware:*:*:*:*:*:*:*:*
Shodan: http.html:"SolarView Compact"
Shodan: http.favicon.hash:"-244067125"
Shodan: http.html:"solarview compact"
FOFA: body="solarview compact"
FOFA: icon_hash="-244067125"

Source: ProjectDiscovery

References

3