Local File Inclusion in Danfoss AK-EM100
CVE-2023-22586
7.7HIGH
What is CVE-2023-22586?
The Danfoss AK-EM100 web applications are susceptible to a Local File Inclusion vulnerability, allowing attackers to manipulate the file parameter to gain unauthorized access to sensitive files on the web server. This could lead to exposure of critical information and potentially compromise system integrity.
Affected Version(s)
AK-EM100 < 2.2.0.12
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jony Schats (Hackdefense)
Stan Plasmeijer (Hackdefense)
Max van der Horst (DIVD)
