VYPR
Unrated severityNVD Advisory· Published Jun 22, 2023· Updated Jan 16, 2025

Advantech R-SeeNet External Control of File Name or Path

CVE-2023-3256

Description

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Low-level users in Advantech R-SeeNet versions 2.4.22 and prior can read arbitrary local files due to lack of path validation.

Vulnerability

Advantech R-SeeNet versions 2.4.22 and prior contain an External Control of File Name or Path (CWE-73) vulnerability [1]. The application does not properly validate file paths supplied by authenticated low-privilege users, allowing them to access and load the content of arbitrary local files on the system [1].

Exploitation

An attacker with a low-privileged account on the R-SeeNet application can exploit this flaw remotely over the network with low attack complexity [1]. No user interaction is required. The attacker sends crafted requests to manipulate file path references, bypassing intended access restrictions [1].

Impact

Successful exploitation allows the attacker to read arbitrary files from the local filesystem, leading to disclosure of sensitive information such as configuration files containing credentials or other operational data [1]. This can escalate to full system compromise if combined with the hard-coded credential vulnerability (CVE-2023-2611) also present in the same product [1].

Mitigation

Advantech released R-SeeNet version 2.4.23, which fixes the vulnerability [1]. All users should upgrade immediately. The update can be obtained from Advantech's software portal [1]. CISA also recommends following least-privilege principles and minimizing network exposure for control systems as defensive measures [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Advantech/R-SeeNetllm-fuzzy2 versions
    = 2.4.22+ 1 more
    • (no CPE)range: = 2.4.22
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.