MEDIUM · 6.8

CVE-2010-4730

Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100...

Vulnerability Description

Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the page parameter, a different vulnerability than CVE-2009-4463.

CVSS Score

6.8

MEDIUM

AV:N/AC:L/Au:S/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntellicomNetbiter Easyconnect Ec150All versions
IntellicomNetbiter Modbus Rtu-Tcp Gateway Mb100All versions
IntellicomNetbiter Serial Ethernet Server Ss100All versions
IntellicomNetbiter Webscada Ws100All versions
IntellicomNetbiter Webscada Ws200All versions
IntellicomNetbiter Nb100All versions
IntellicomNetbiter Nb200All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4730?

CVE-2010-4730 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100...

How severe is CVE-2010-4730?

CVE-2010-4730 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4730?

Check the references section above for vendor advisories and patch information. Affected products include: Intellicom Netbiter Easyconnect Ec150, Intellicom Netbiter Modbus Rtu-Tcp Gateway Mb100, Intellicom Netbiter Serial Ethernet Server Ss100, Intellicom Netbiter Webscada Ws100, Intellicom Netbiter Webscada Ws200.