Path Traversal in Campbell Scientific CSI Web Server and RTMC
Vulnerability Description
The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression can lead to a path traversal vulnerability. This command combined with a specially crafted expression allows anonymous, unauthenticated access (allowed by default) by an attacker to files and directories outside of the webserver root directory they should be restricted to.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5433
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Patrick K. Sheehan, Grant Hume, and Donald Macary reported these vulnerabilities to CISA.
Affected Vendor
Campbell Scientific
View all reports →