Impact
The vulnerability stems from improper limitation of a pathname to a restricted directory, allowing an attacker to construct a path that escapes the intended boundary and accesses arbitrary files. This can lead to exposure of sensitive configuration files, credentials, or other critical data, potentially compromising confidentiality and integrity of the system.
Affected Systems
The affected product is ABB Mint Workbench I. The vulnerability exists in all releases through version 5876.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. No EPSS value is available at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector likely involves components that accept user-supplied file paths, such as web or API interfaces, and the vulnerability can be exploited if an attacker has sufficient privilege to submit a crafted path. The risks involve read or write access to files outside the permitted directory, potentially leading to data breach or system compromise.
OpenCVE Enrichment