IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22
The affected product could allow a remote unauthenticated attacker to read arbitrary files on the device.
MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306
The affected product could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS update service.
https://www.us-cert.gov/ics/advisories/icsa-20-084-02