MEDIUM · 6.8

CVE-2010-4731

Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter N...

Vulnerability Description

Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a full pathname in the file parameter, a different vulnerability than CVE-2009-4463.

CVSS Score

6.8

MEDIUM

AV:N/AC:L/Au:S/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntellicomNetbiter Easyconnect Ec150All versions
IntellicomNetbiter Modbus Rtu-Tcp Gateway Mb100All versions
IntellicomNetbiter Serial Ethernet Server Ss100All versions
IntellicomNetbiter Webscada Ws100All versions
IntellicomNetbiter Webscada Ws200All versions
IntellicomNetbiter Nb100All versions
IntellicomNetbiter Nb200All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4731?

CVE-2010-4731 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter N...

How severe is CVE-2010-4731?

CVE-2010-4731 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4731?

Check the references section above for vendor advisories and patch information. Affected products include: Intellicom Netbiter Easyconnect Ec150, Intellicom Netbiter Modbus Rtu-Tcp Gateway Mb100, Intellicom Netbiter Serial Ethernet Server Ss100, Intellicom Netbiter Webscada Ws100, Intellicom Netbiter Webscada Ws200.