Back to Database
Status published
High
CVE-2017-20184
Carlo Gavazzi Powersoft prone to Path Traversal
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20184
Credits & Attribution
No credits recorded in the NVD database.
References
More from Carlo Gavazzi
View All →CVE-2022-28816
Reflected XSS in Carlo Gavazzi UWP 3.0
Medium
6.1
CVE-2022-28815
SQL-Injection in Carlo Gavazzi UWP 3.0 Sentilo Proxy
Low
2.7
CVE-2022-28814
Path traversal in Carlo Gavazzi UWP 3.0 could lead to full device access
Critical
9.8
CVE-2022-28813
SQL-injection in Car Park Server 3.0 allows for full database access.
High
7.5
CVE-2022-28812
Use of Hard-coded Credentials in UWP3.0 allows SuperUser authentication bypass in Car Park Server.
Critical
9.8
Affected Vendor
Carlo Gavazzi
View all reports →Affected Software
Powersoft
Vulnerable Versions:
0
Timeline
Official Publish:
May 4th, 2023
Last Modified:
January 31st, 2025
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N