Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended directory.
The vulnerability occurs in the 'name' parameter of the download_debuglog_file.php endpoint, intended for downloading debug log files. An attacker can manipulate the value of this parameter by injecting path traversal sequences (e.g., '../') to exit the intended directory and gain access to arbitrary files in the server file system. The attack requires no authentication — the endpoint is publicly accessible.
An attacker can read arbitrary files from the server file system, including configuration files, credentials, private keys or other sensitive information, which may lead to further system compromise.
Apply patches available from the manufacturer according to the references. Detailed information is available in the ICS-CERT advisory ICSA-26-113-06 published by CISA. As a temporary measure, it is recommended to restrict network access to the download_debuglog_file.php endpoint using firewall or ACL rules.
Intrado 911 Emergency Gateway (EGW) in versions 5.x, 6.x and 7.x
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X