|
Description: | | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files. |
|
Impact: | | An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information. |
|
Affected OS: | | Windows, Others |
|
Reference: | | https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01 ZeroDayInitiative:ZDI-21-447
|
|