Impact
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in Erlang OTP's tftp_file module within the erlang/otp, inets, and tftp applications allows attackers to request files outside the designated directory by including traversal characters in a TFTP request. The vulnerability is associated with the program files lib/tftp/src/tftp_file.erl and src/tftp_file.erl and affects OTP 17.0 through before 28.3.2, OTP 27.3.4.8, OTP 26.2.5.17, tftp 1.0 before 1.2.4, 1.2.2.1, 1.1.1.1, and inets 5.10 before 7.0. If exploited, the attacker can read arbitrary files on the host, compromising confidentiality. The weakness is classified as CWE-22 and CWE-23.
Affected Systems
Erlang OTP versions 17.0 up to but not including 28.3.2, including the specific releases 27.3.4.8 and 26.2.5.17, Erlang tftp releases 1.0 through before 1.2.4, 1.2.2.1, and 1.1.1.1, and Erlang inets releases 5.10 through before 7.0.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. It appears to be exploitable via the TFTP service; an attacker who can send a crafted TFTP request containing traversal sequences may read arbitrary files on the server.
OpenCVE Enrichment
Debian DLA