Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEmerson Dixell Xweb 500
HWEmersonall versionsEmerson Dixell Xweb 500 Firmware
OSEmersonall versions
Related vulnerabilities
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential att...
Emerson Rosemount GC370XA/GC700XA/GC1500XA — zdalne RCE jako root bez uwierzytelnienia
Authentication bypass w urządzeniach Emerson ROC800-Series RTU
Emerson ROC/FloBoss RTU — niezabezpieczone operacje na systemie plików przez ROC protocol
RCE z uprawnieniami systemowymi w Emerson OpenEnterprise SCADA Server