GHSA-6rrq-ffwf-5j3wMedium
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted...
🔗 CVE IDs covered (1)
📋 Description
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to read arbitrary files with the privileges of the RevPiPyLoad daemon, including sensitive configuration and credential material, by sending crafted requests to the local management service.