Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 ...
High severity
Unreviewed
Published
Sep 1, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Aug 31, 2022
Published to the GitHub Advisory Database
Sep 1, 2022
Last updated
Jan 29, 2023
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.
References