← back
CVE-2023-31166mediumCWE-22

Improper Limitation of a Pathname to a Restricted Directory

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.1epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
In short

A vulnerability in the SEL RTAC Web Interface allows an authenticated user to create folders in any location on the server's file system, bypassing normal restrictions. This could be exploited to disrupt system operations or prepare for further attacks.

Technical detail

A path traversal vulnerability in the SEL RTAC Web Interface fails to properly validate user-supplied pathnames, allowing authenticated attackers to create directories outside intended restricted directories. The vulnerability requires prior authentication and could enable arbitrary file system manipulation with potential impact on system integrity and availability.

Summary generated and translated by AI from the official description.
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to create folders in arbitrary paths of the file system. See SEL Service Bulletin dated 2022-11-15 for more details.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N