CVE-2023-3329
Last modified
CVE-2023-3329 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Spidercontrol | Scadawebserver | <= 2.08 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-173-03Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-173-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3329?
How severe is CVE-2023-3329?
How do I fix CVE-2023-3329?
Are you affected by CVE-2023-3329?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
