Description
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
Published: 2023-08-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Upgrade to the latest patch, which is version 3.3.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-29802 Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
History

Wed, 02 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 12:00:00 +0000

Type Values Removed Values Added
Description Due to improper restriction, attackers could retrieve and read system files of the underlying server through the XML interface. Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
Title Path Traversal in Danfoss AK-SM800A Authneticated Path Traversal in Danfoss AK-SM800A
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Danfoss Ak-sm 800a Ak-sm 800a Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published:

Updated: 2025-07-19T05:15:44.063Z

Reserved: 2023-02-16T14:22:41.966Z

Link: CVE-2023-25914

cve-icon Vulnrichment

Updated: 2024-08-02T11:32:12.736Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-21T21:15:08.970

Modified: 2025-01-17T17:54:40.107

Link: CVE-2023-25914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses