CVE Published: 12/03/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: INCIBE |
Vendor: Badger Meter |
Product: Monitool Status : PUBLISHED
CVE-2024-1303 Description
Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authenticated attacker to retrieve any file from the device using the download-file functionality.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N