S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 7, 2024

CVE-2024-8752 Scanner

CVE-2024-8752 scanner - Directory Traversal vulnerability in WebIQ

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8752
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebIQby Smart HMI
2.15.19
webiqby beijerelectronics
2.15.19
Updated Aug 22, 2026View on NVD →
Detail

WebIQ is an innovative HMI software designed for use in industrial automation systems. Primarily used by engineering firms and manufacturing facilities, it enables user-friendly, web-based interface design and real-time monitoring. WebIQ facilitates rapid HMI development, reducing time-to-market for machine and process control systems. With a strong focus on usability and versatility, WebIQ is commonly integrated into automation systems across various industries. It supports a range of system architectures, including both on-premises and cloud-based installations.


This Directory Traversal vulnerability in WebIQ allows unauthorized attackers to access files outside the intended directory. By manipulating URL paths, attackers can read sensitive files on the host system. The exploit is achieved remotely without requiring special privileges, potentially exposing confidential data. As a high-severity issue, it poses a significant risk to affected systems.


The vulnerability exists in WebIQ’s web-based interface, specifically in path handling for file requests. Attackers use crafted HTTP requests to navigate out of the root directory by leveraging path traversal sequences such as ../. This allows unauthorized access to critical system files, such as configuration files or sensitive user data. The HTTP request targeting the /windows/win.ini endpoint provides a practical example of how attackers can confirm file access. This specific weakness in directory traversal management may expose WebIQ installations to data leakage risks.


Exploiting this vulnerability could allow attackers to read arbitrary files on the affected server, leading to exposure of sensitive data. Confidential configurations, database credentials, and user information may be exposed, increasing the risk of further compromises. If sensitive files contain additional system or user information, attackers could leverage this data in further attacks. Loss of sensitive information could also result in compliance violations and reputational harm.


S4E offers a comprehensive platform to ensure your digital assets remain protected from vulnerabilities such as the WebIQ Directory Traversal issue. With our advanced scanner, quickly detect critical risks and gain insights into the potential security flaws within your network. Our user-friendly interface provides detailed vulnerability reports and actionable guidance to secure your assets. By joining SecurityforEveryone, take advantage of a secure platform that constantly monitors and safeguards your digital environment, enhancing your cybersecurity posture.

References:

Solution Advice
  • Update WebIQ to the latest secure version if available.
  • Implement stricter file permissions to limit unauthorized access to sensitive files.
  • Configure WebIQ settings to restrict direct access to system files.
  • Regularly review and apply security patches and updates.
  • Monitor logs for unusual requests indicative of path traversal attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.