Path Traversal Vulnerability Leads to System Paralysis or Remote Control
CVE-2024-10313

8HIGH

Key Information:

Vendor
CVE Published:
24 October 2024

What is CVE-2024-10313?

The iniNet Solutions SpiderControl SCADA PC HMI Editor is susceptible to a path traversal vulnerability that occurs when the software processes a specially crafted ā€˜ems' project template file. This vulnerability allows an attacker to manipulate file paths, enabling the application to write files to arbitrary directories. This behavior can result in the overwriting of critical system files, potentially leading to system paralysis, or modification of startup items, which may facilitate unauthorized remote control of the system.

Affected Version(s)

SpiderControl SCADA PC HMI Editor 8.10.00.00

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

elcazator from ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc. reported this vulnerability to CISA.
.
CVE-2024-10313 : Path Traversal Vulnerability Leads to System Paralysis or Remote Control