CVE-2016-9339

An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.
References
Link Resource
http://www.securityfocus.com/bid/94776 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-343-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:macgregor:interschalt_vdr_g4e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:macgregor:interschalt_vdr_g4e:-:*:*:*:*:*:*:*

History

22 Jun 2021, 20:25

Type Values Removed Values Added
CPE cpe:2.3:o:interschalt_maritime_systems:vdr_g4e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:interschalt_maritime_systems:vdr_g4e:-:*:*:*:*:*:*:*
cpe:2.3:o:macgregor:interschalt_vdr_g4e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:macgregor:interschalt_vdr_g4e:-:*:*:*:*:*:*:*

Information

Published : 2017-02-13 21:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-9339

Mitre link : CVE-2016-9339

CVE.ORG link : CVE-2016-9339


JSON object : View

Products Affected

macgregor

  • interschalt_vdr_g4e
  • interschalt_vdr_g4e_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')