7.1

CVE-2023-47613

A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Telit ≫ Bgs5 Firmware Version -
   Telit ≫ Bgs5 Version -
Telit ≫ Ehs5 Firmware Version -
   Telit ≫ Ehs5 Version -
Telit ≫ Ehs6 Firmware Version -
   Telit ≫ Ehs6 Version -
Telit ≫ Ehs8 Firmware Version -
   Telit ≫ Ehs8 Version -
Telit ≫ Pds5 Firmware Version -
   Telit ≫ Pds5 Version -
Telit ≫ Pds6 Firmware Version -
   Telit ≫ Pds6 Version -
Telit ≫ Pds8 Firmware Version -
   Telit ≫ Pds8 Version -
Telit ≫ Els61 Firmware Version -
   Telit ≫ Els61 Version -
Telit ≫ Els81 Firmware Version -
   Telit ≫ Els81 Version -
Telit ≫ Pls62 Firmware Version -
   Telit ≫ Pls62 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.143
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Kaspersky 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CWE-23 Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

https://ics-cert.kaspersky.com/advisories/2023/11/08/klcert-22-211-telit-cinterion-thales-gemalto-modules-relative-path-traversal/
Third Party Advisory