There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-49963 There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.
Fixes

Solution

This vulnerability, has been fixed by Generex team in CS141 version 2.12, released on December 2022.


Workaround

No workaround given by the vendor.

History

Wed, 12 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-02-12T14:52:45.725Z

Reserved: 2022-12-12T00:00:00.000Z

Link: CVE-2022-47188

cve-icon Vulnrichment

Updated: 2024-08-03T14:47:29.466Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T22:15:07.227

Modified: 2024-11-21T07:31:40.420

Link: CVE-2022-47188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.