CVE-2015-6459
GE MDS PulseNET FileDownloadServlet Directory Traversal Information Disclosure And Deletion Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
Vulnerabilidad de salto de ruta absoluta en la funcionalidad de descarga en FileDownloadServlet en GE Digital Energy MDS PulseNET y MDS PulseNET Enterprise en versiones anteriores a 3.1.5, permite a atacantes remotos leer o eliminar archivos arbitrarios a través de un nombre de ruta completo.
This vulnerability allows remote attackers to read and delete arbitrary files on vulnerable installations of GE MDS PulseNET. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the FileDownloadServlet. By specifying a filename including directory traversal, an attacker can read and then delete an arbitrary file on the system. The read and subsequent deletion will be performed under the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-08-17 CVE Reserved
- 2015-09-16 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://zerodayinitiative.com/advisories/ZDI-15-439 | X_refsource_misc | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-258-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.gedigitalenergy.com/app/resources.aspx?prod=pulsenet&type=9 | 2015-09-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ge Search vendor "Ge" | Mds Pulsenet Search vendor "Ge" for product "Mds Pulsenet" | <= 3.1.3 Search vendor "Ge" for product "Mds Pulsenet" and version " <= 3.1.3" | - |
Affected
| ||||||
Ge Search vendor "Ge" | Mds Pulsenet Search vendor "Ge" for product "Mds Pulsenet" | <= 3.1.3 Search vendor "Ge" for product "Mds Pulsenet" and version " <= 3.1.3" | enterprise |
Affected
|