iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal
vulnerability. When the software loads a malicious ‘ems' project
template file constructed by an attacker, it can write files to
arbitrary directories. This can lead to overwriting system files,
causing system paralysis, or writing to startup items, resulting in
remote control.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Spidercontrol
Spidercontrol scada Pc Hmi Editor |
|
CPEs | cpe:2.3:a:spidercontrol:scada_pc_hmi_editor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Spidercontrol
Spidercontrol scada Pc Hmi Editor |
|
Metrics |
ssvc
|
Thu, 24 Oct 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control. | |
Title | iniNet Solutions SpiderControl SCADA PC HMI Editor Path Traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-10-24T17:41:56.069Z
Updated: 2024-10-24T18:29:45.979Z
Reserved: 2024-10-23T18:25:15.297Z
Link: CVE-2024-10313
Vulnrichment
Updated: 2024-10-24T18:29:39.472Z
NVD
Status : Awaiting Analysis
Published: 2024-10-24T18:15:05.920
Modified: 2024-10-25T12:56:07.750
Link: CVE-2024-10313
Redhat
No data.