HTTP: Schneider Electric IIoT Monitor Zip Directory Traversal
This signature detects attempts to exploit a known vulnerability against Schneider Electric IIoT Monitor. A successful attack can lead to arbitrary code execution.
Extended Description
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.
Affected Products
Schneider-electric iiot_monitor
References
BugTraq: 106484
CVE: CVE-2018-7836
URL: http://www.zerodayinitiative.com/advisories/zdi-19-021/ http://www.zerodayinitiative.com/advisories/zdi-19-022/ http://www.zerodayinitiative.com/advisories/zdi-19-029/ http://www.zerodayinitiative.com/advisories/zdi-19-030/ http://www.zerodayinitiative.com/advisories/zdi-19-032/ https://www.schneider-electric.com/en/download/document/sevd-2018-354-03/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Schneider-electric
7.5