CVE-2024-10313
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
24/10/2024
Last modified:
25/10/2024
Description
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal <br />
vulnerability. When the software loads a malicious ‘ems&#39; project <br />
template file constructed by an attacker, it can write files to <br />
arbitrary directories. This can lead to overwriting system files, <br />
causing system paralysis, or writing to startup items, resulting in <br />
remote control.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.00
Severity 3.x
HIGH



