// For flags

CVE-2015-0984

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.

Vulnerabilidad de salto de directorio en el servidor FTP en los controladores Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, y XL1000C1000U 600 I/O UUKL anterior a 2.04.01 permite a atacantes remotos leer ficheros bajo el root web, y como consecuencia obtener acceso al inicio de sesión de administración, a través de un nombre de ruta manipulado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-01-10 CVE Reserved
  • 2015-03-31 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c100 104 I\/o
Search vendor "Honeywell" for product "Excel Web Xl 1000c100 104 I\/o"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c100 104 I\/o" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c1000 600 I\/o
Search vendor "Honeywell" for product "Excel Web Xl 1000c1000 600 I\/o"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c1000 600 I\/o" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c1000 600 I\/o Uukl
Search vendor "Honeywell" for product "Excel Web Xl 1000c1000 600 I\/o Uukl"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c1000 600 I\/o Uukl" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c100u 104 I\/o Uukl
Search vendor "Honeywell" for product "Excel Web Xl 1000c100u 104 I\/o Uukl"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c100u 104 I\/o Uukl" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c50 52 I\/o
Search vendor "Honeywell" for product "Excel Web Xl 1000c50 52 I\/o"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c50 52 I\/o" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c500 300 I\/o
Search vendor "Honeywell" for product "Excel Web Xl 1000c500 300 I\/o"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c500 300 I\/o" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c500 300 I\/o Uukl
Search vendor "Honeywell" for product "Excel Web Xl 1000c500 300 I\/o Uukl"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c500 300 I\/o Uukl" and version " <= 2.04.00"
-
Affected
Honeywell
Search vendor "Honeywell"
Excel Web Xl 1000c50u 52 I\/o Uukl
Search vendor "Honeywell" for product "Excel Web Xl 1000c50u 52 I\/o Uukl"
<= 2.04.00
Search vendor "Honeywell" for product "Excel Web Xl 1000c50u 52 I\/o Uukl" and version " <= 2.04.00"
-
Affected