9.8
CVE-2026-28701
- EPSS 0.63%
- Veröffentlicht 26.06.2026 22:40:03
- Zuletzt bearbeitet 06.07.2026 17:59:43
- CVE-Watchlists
- Unerledigt
Daktronics Controller Firmware Path Traversal
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Daktronics ≫ Dmp-5000 Firmware Version < 8.117.0.0
Daktronics ≫ Dmp-5000 Firmware Version >= 9.0.0.0 < 9.43.0.0
Daktronics ≫ Dmp-5000 Firmware Version >= 10.0.0.0 < 10.34.0.0
Daktronics ≫ Dmp-8000 Firmware Version < 8.117.0.0
Daktronics ≫ Dmp-8000 Firmware Version >= 9.0.0.0 < 9.43.0.0
Daktronics ≫ Dmp-8000 Firmware Version >= 10.0.0.0 < 10.34.0.0
Daktronics ≫ Vfc-dmp-5000 Firmware Version < 8.117.0.0
Daktronics ≫ Vfc-dmp-5000 Firmware Version >= 9.0.0.0 < 9.43.0.0
Daktronics ≫ Vfc-dmp-5000 Firmware Version >= 10.0.0.0 < 10.34.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.466 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| DHS.gov | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| DHS.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json