MICROSENS NMP Web+ Path Traversal Vulnerability Allowing Arbitrary File Overwrite and Code Execution
Vulnerability
A path traversal vulnerability has been identified in MICROSENS NMP Web+ versions through 3.2.5. This vulnerability allows an unauthenticated attacker to overwrite files and execute arbitrary code on the affected system.
Impact
Exploitation of this vulnerability could lead to unauthorized file overwriting and execution of arbitrary code on the system.
Remediation
Users are advised to update to NMP Web+ Version 3.3.0 for Windows and Linux. For additional guidance, CISA recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods such as Virtual Private Networks (VPNs).
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
