{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105275", "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "state": "PUBLISHED", "assignerShortName": "icscert", "dateReserved": "2026-10-05T21:19:46.304Z", "datePublished": "2026-10-08T21:18:29.051Z", "dateUpdated": "2026-10-09T13:21:19.937Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert", "dateUpdated": "2026-10-08T21:20:07.459Z" }, "title": "Satel Netco Design Relative Path Traversal", "datePublic": "2026-10-08T15:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-23", "description": "CWE-23 Relative path traversal", "type": "CWE" } ] } ], "affected": [ { "vendor": "Satel", "product": "Satel Netco Design", "versions": [ { "status": "affected", "version": "0", "lessThan": "v2.1.7", "versionType": "custom" }, { "status": "unaffected", "version": "v2.1.7" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system." } ] } ], "references": [ { "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03" }, { "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-03.json" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 4.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } } ], "solutions": [ { "lang": "en", "value": "Satel advises users to update to Satel Netco Design v2.1.7.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Satel advises users to update to Satel Netco Design v2.1.7." } ] } ], "credits": [ { "lang": "en", "value": "Alex Williams of Pellera Technologies reported this vulnerability to CISA.", "type": "finder" } ], "source": { "advisory": "ICSA-26-281-03", "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-09T13:21:10.309403Z", "id": "CVE-2026-105275", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-09T13:21:19.937Z" } } ] } }