CVE-2023-32767 Information

Description

The web interface of Symcon IP-Symcon before 6.3 (i.e. before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL.

Reference

https://community.symcon.de/t/ip-symcon-6-3-stable-changelog/40276/87 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-014.txt

Share on: