Siemens SIMATIC TIA Portal Path Traversal (SSA-116924)

high Nessus Plugin ID 174624

Version 1.20

Mar 19, 2024, 6:40 PM

  • Logic Changes (Improving logging to reduce disk space usage)

Plugin Feed: 202403191840

Version 1.17

Feb 9, 2024, 11:22 AM

  • New

Plugin Feed: 202402091122

Version 1.16

Jan 2, 2024, 2:43 PM

  • Logic Changes (typo)

Plugin Feed: 202401021443

Version 1.14

Nov 24, 2023, 10:09 AM

  • Logic Changes (add fixed version)

Plugin Feed: 202311241009

Version 1.12

Sep 26, 2023, 8:16 PM

  • Logic Changes

Plugin Feed: 202309262016

Version 1.11

Jul 17, 2023, 5:15 PM

  • Logic Changes (Make torture_cgi library PCP clean and consolidate utf16_to_ascii())

Plugin Feed: 202307171715

Version 1.10

Jun 20, 2023, 9:07 PM

  • Logic Changes (Temporarily limit debug logging)

Plugin Feed: 202306202107

Version 1.8

Jun 1, 2023, 5:27 AM

  • Logic Changes (Better logging)

Plugin Feed: 202306010527

Version 1.7

May 14, 2023, 10:07 AM

  • CVSSv3 score source (set to "CVE-2023-26293")
  • Exploit attributes ("Exploit available" set to "False")
  • CVSS metrics ("CVSSv2 score" changed from 7.2 to 6.8. "CVSSv2 vector" changed from "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C" to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:P". "CVSSv3 score" changed from 7.8 to 7.3. "CVSSv3 vector" changed from "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L")
  • CVSSv2 severity (based on CVE-2023-26293, severity decreased from "High" to "Medium")

Plugin Feed: 202305141007

Version 1.6

May 14, 2023, 6:02 AM

  • CVSSv2 severity (based on CVE-2023-26293, severity decreased from "High" to "Medium")
  • CVSS metrics ("CVSSv2 score" changed from 7.2 to 6.8. "CVSSv2 vector" changed from "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C" to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:P". "CVSSv3 score" changed from 7.8 to 7.3. "CVSSv3 vector" changed from "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L")
  • Exploit attributes ("Exploit available" set to "False")
  • CVSSv3 score source (set to "CVE-2023-26293")

Plugin Feed: 202305140602

Version 1.5

May 14, 2023, 2:08 AM

  • CVSSv3 score source (set to "CVE-2023-26293")
  • CVSS metrics ("CVSSv2 score" changed from 7.2 to 6.8. "CVSSv2 vector" changed from "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C" to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:P". "CVSSv3 score" changed from 7.8 to 7.3. "CVSSv3 vector" changed from "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" to "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L")
  • CVSSv2 severity (based on CVE-2023-26293, severity decreased from "High" to "Medium")
  • Exploit attributes ("Exploit available" set to "False")

Plugin Feed: 202305140208

Version 1.4

May 4, 2023, 4:01 PM

  • Detection (replaced inaccurate fixed_version)

Plugin Feed: 202305041601

Version 1.3

May 1, 2023, 9:07 PM

  • Detection (Make and use compatibility wrapper for running commands on scanner localhost to handle deprecation of pread().)

Plugin Feed: 202305012107

Version 1.1

Apr 24, 2023, 6:22 PM

  • Exploit attributes ("Exploit available" set to "False". "Exploit available" set to "False". "Exploit available" set to "False". "Exploitability ease" set to "No known exploits are available". "Exploitability ease" set to "No known exploits are available")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:U/RL:OF/RC:C". "CVSSv2 temporal vector" set to "CVSS2#E:U/RL:OF/RC:C". "CVSSv2 temporal vector" set to "CVSS2#E:U/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:U/RL:O/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:U/RL:O/RC:C")

Plugin Feed: 202304241822

Version 1.0

Apr 21, 2023, 4:06 PM

  • New

Plugin Feed: 202304211606

* Changelogs are generally available for changes made after Nov 1, 2022