CVE-2023-0956 Information
Aug 05, 2023
cve
Description
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname which could allow an unauthenticated attacker to read files on the system.
Reference
https://cert.pl/posts/2023/07/CVE-2023-0956/ https://www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956 https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-03
Share on: