High severity7.5NVD Advisory· Published Aug 3, 2023· Updated Jun 17, 2026
CVE-2023-0956
CVE-2023-0956
Description
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
63.2+ 4 more
- (no CPE)range: 3.2
- cpe:2.3:a:tel-ster:telwin_scada_webinterface:*:*:*:*:*:*:*:*range: >=3.2,<6.2
- cpe:2.3:a:tel-ster:telwin_scada_webinterface:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:tel-ster:telwin_scada_webinterface:9.0:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- cert.pl/posts/2023/07/CVE-2023-0956/nvdThird Party Advisory
- www.cisa.gov/news-events/ics-advisories/icsa-23-215-03nvdThird Party AdvisoryUS Government Resource
- www.tel-ster.pl/index.php/telwin-scada/nowosci/372-telwin-scada-podatnosc-cve-2023-0956nvdVendor Advisory
News mentions
0No linked articles in our index yet.