#VU27556 Path traversal in FW-50 Remote Telemetry Unit - CVE-2020-10634
Published: May 6, 2020
FW-50 Remote Telemetry Unit
SAE IT-systems
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
This vulnerability affects the following version of FW-50 RTU:
- Series: 5 Series; CPU-type: CPU-5B; Hardware Revision: 2; CPLD Revision: 6