Impact
Satel Netco Design versions before 2.1.7 allow an authenticated user with Viewer privileges to exploit a relative path traversal flaw in the data export feature. The flaw enables the attacker to write content influenced by the user to arbitrary file system locations that the application service can access. As a result, the attacker can create or modify files, and in specific circumstances the attacker may achieve arbitrary code execution, compromising both confidentiality and integrity of the system.
Affected Systems
The vulnerability affects Satel Netco Design deployments running any version prior to 2.1.7. Users of the legacy product should verify the exact version of their installation and consider the upgrade path provided by the vendor.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. The attack requires the target to be authenticated with Viewer privileges, limiting the potential attacker base to those who can access the system. Nonetheless, the combination of local authentication and file write capabilities presents a significant risk if an attacker can compromise or elevate a user account.
OpenCVE Enrichment