CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
The vulnerability is classified as CWE-35 (Path Traversal: '.../.../') and involves insufficient path validation during file upload operations. An authenticated attacker can specify a target path containing directory traversal sequences, which allows saving arbitrary files outside the intended target directory. As a result, it is possible to place malicious files in multiple locations on the device's file system.
An attacker can overwrite critical system files or place malicious code anywhere in the device's file system, which may lead to permanent takeover of the intercom, disruption of its operation, or use it as an entry point to the network.
Apply patches available from the manufacturer according to the references. It is recommended to restrict access to the device management interface to trusted IP addresses only and use strong authentication. Detailed information is available in the CISA advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01
CyberData 011209 SIP Emergency Intercom and related firmware — specific versions indicated in the manufacturer's references (CISA ICS-CERT advisory ICSA-25-155-01)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCyberdata 011209 Sip Emergency Intercom
HWCyberdataall versionsCyberdata 011209 Sip Emergency Intercom Firmware
OSCyberdata< 22.0.1
Related vulnerabilities
CyberData 011209 Intercom — ominięcie uwierzytelnienia w interfejsie Web
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a...
CyberData 011209 Intercom does not properly store or protect web server admin credentials.
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQ...