Impact
A path traversal issue exists in the web portal of the SenNet Datalogger Serie 200, allowing an authenticated user to modify the URL and access any file or directory readable by the web server process. Successful exploitation would give the attacker read access to system files that may contain confidential data.
Affected Systems
The vulnerability affects Satel Iberia’s SenNet Datalogger Serie 200, specifically firmware versions up to V7.0m-1.53h. Satel Iberia has released a fix in version V7.2a.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score is not available, so the probability of exploitation is unknown. Because the flaw requires valid authentication to the web portal, the risk is confined to users who can log in. If an attacker gains authenticated access, they could read any file under the web server’s privilege level, potentially exposing sensitive system configuration and other confidential information.
OpenCVE Enrichment