ID

VAR-201505-0322


CVE

CVE-2015-3939


TITLE

IDS RTU 850 Series Directory Traversal Vulnerability

Trust: 0.8

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03655

DESCRIPTION

Directory traversal vulnerability in the NC854 and NC856 modules for IDS RTU 850C devices allows remote authenticated users to read arbitrary files via unspecified vectors involving an internal web server, as demonstrated by reading a TELNET credentials file. NC854 and NC856 modules for IDS RTU 850C devices are communication modules used by German IDS for automation and remote control equipment. A directory traversal vulnerability exists in the NC854 and NC856 modules of the IDS RTU 850C device. A remote attacker can read arbitrary files with the help of an intranet server. IDS RTU 850 series is prone to a directory-traversal vulnerability. Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to overwrite arbitrary files in the context of the application. This may aid in further attacks

Trust: 2.61

sources: NVD: CVE-2015-3939 // JVNDB: JVNDB-2015-002890 // CNVD: CNVD-2015-03655 // BID: 74900 // IVD: 8da987bc-2351-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03655

AFFECTED PRODUCTS

vendor:idsmodel:nc856scope:eqversion: -

Trust: 1.6

vendor:idsmodel:nc854scope:eqversion: -

Trust: 1.6

vendor:idsmodel:nc854scope: - version: -

Trust: 0.8

vendor:idsmodel:nc856scope: - version: -

Trust: 0.8

vendor:idsmodel:rtu 850cscope: - version: -

Trust: 0.6

vendor:idsmodel:nc856scope:eqversion:0

Trust: 0.3

vendor:idsmodel:nc854scope:eqversion:0

Trust: 0.3

vendor:nc854model: - scope:eqversion: -

Trust: 0.2

vendor:nc856model: - scope:eqversion: -

Trust: 0.2

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03655 // BID: 74900 // JVNDB: JVNDB-2015-002890 // CNNVD: CNNVD-201505-612 // NVD: CVE-2015-3939

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3939
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-3939
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-03655
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201505-612
value: MEDIUM

Trust: 0.6

IVD: 8da987bc-2351-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2015-3939
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-03655
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:L/AU:S/C:N/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 8da987bc-2351-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 8.5
vectorString: AV:N/AC:L/AU:S/C:N/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03655 // JVNDB: JVNDB-2015-002890 // CNNVD: CNNVD-201505-612 // NVD: CVE-2015-3939

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.8

sources: JVNDB: JVNDB-2015-002890 // NVD: CVE-2015-3939

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-612

TYPE

Path traversal

Trust: 0.8

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201505-612

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002890

PATCH

title:Top Pageurl:http://www.ids.de/en/home.html

Trust: 0.8

sources: JVNDB: JVNDB-2015-002890

EXTERNAL IDS

db:NVDid:CVE-2015-3939

Trust: 3.5

db:ICS CERTid:ICSA-15-148-01

Trust: 3.3

db:BIDid:74900

Trust: 1.9

db:CNVDid:CNVD-2015-03655

Trust: 0.8

db:CNNVDid:CNNVD-201505-612

Trust: 0.8

db:JVNDBid:JVNDB-2015-002890

Trust: 0.8

db:IVDid:8DA987BC-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 8da987bc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03655 // BID: 74900 // JVNDB: JVNDB-2015-002890 // CNNVD: CNNVD-201505-612 // NVD: CVE-2015-3939

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-15-148-01

Trust: 3.3

url:http://www.securityfocus.com/bid/74900

Trust: 1.6

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3939

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3939

Trust: 0.8

url:http://www.ids.de/en/products/automation-and-telecontrol/ids-850.html

Trust: 0.3

sources: CNVD: CNVD-2015-03655 // BID: 74900 // JVNDB: JVNDB-2015-002890 // CNNVD: CNNVD-201505-612 // NVD: CVE-2015-3939

CREDITS

Benjamin Kahler and Sebastian Kraemer of HSASec.

Trust: 0.3

sources: BID: 74900

SOURCES

db:IVDid:8da987bc-2351-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-03655
db:BIDid:74900
db:JVNDBid:JVNDB-2015-002890
db:CNNVDid:CNNVD-201505-612
db:NVDid:CVE-2015-3939

LAST UPDATE DATE

2025-04-13T23:25:14.247000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-03655date:2015-06-10T00:00:00
db:BIDid:74900date:2015-05-28T00:00:00
db:JVNDBid:JVNDB-2015-002890date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-612date:2015-06-01T00:00:00
db:NVDid:CVE-2015-3939date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:IVDid:8da987bc-2351-11e6-abef-000c29c66e3ddate:2015-06-10T00:00:00
db:CNVDid:CNVD-2015-03655date:2015-06-10T00:00:00
db:BIDid:74900date:2015-05-28T00:00:00
db:JVNDBid:JVNDB-2015-002890date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-612date:2015-05-31T00:00:00
db:NVDid:CVE-2015-3939date:2015-05-31T17:59:07.077