In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.
History

Fri, 25 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Indu-sol
Indu-sol profinet-inspektor Nt
Indu-sol profinet-inspektor Nt Firmware
CPEs cpe:2.3:h:indu-sol:profinet-inspektor_nt:-:*:*:*:*:*:*:*
cpe:2.3:o:indu-sol:profinet-inspektor_nt_firmware:*:*:*:*:*:*:*:*
Vendors & Products Indu-sol
Indu-sol profinet-inspektor Nt
Indu-sol profinet-inspektor Nt Firmware

Tue, 22 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Indo Sol
Indo Sol profinet Inspektor Nt
CPEs cpe:2.3:a:indo_sol:profinet_inspektor_nt:*:*:*:*:*:*:*:*
Vendors & Products Indo Sol
Indo Sol profinet Inspektor Nt
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-26T00:00:00.000Z

Updated: 2025-04-22T16:14:10.733Z

Reserved: 2023-12-03T00:00:00.000Z

Link: CVE-2023-49960

cve-icon Vulnrichment

Updated: 2024-08-02T22:09:49.586Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-26T16:27:47.373

Modified: 2025-04-25T18:09:33.990

Link: CVE-2023-49960

cve-icon Redhat

No data.