PatchSiren cyber security CVE debrief
CVE-2024-5433 Campbell Scientific CVE debrief
A path traversal vulnerability in Campbell Scientific CSI Web Server allows unauthenticated remote attackers to access files outside the webserver root directory. The vulnerability exists in a command that returns the most recent file matching a given expression; when combined with a specially crafted expression, this permits directory traversal. Anonymous access is enabled by default, exposing affected systems to unauthorized file access without authentication. The vulnerability affects CSI Web Server versions ≤1.6 and RTMC Pro versions ≤5.0. CISA published advisory ICSA-24-149-01 on May 28, 2024, coordinating with Campbell Scientific on remediation.
- Vendor
- Campbell Scientific
- Product
- RTMC Pro
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-28
- Original CVE updated
- 2024-05-28
- Advisory published
- 2024-05-28
- Advisory updated
- 2024-05-28
Who should care
Organizations operating Campbell Scientific data acquisition systems in industrial, environmental, or research environments; OT security teams managing remote monitoring infrastructure; asset owners with publicly accessible CSI Web Server deployments.
Technical summary
The CSI Web Server implements a command to retrieve the most recent file matching a specified expression. Insufficient input validation on this expression parameter allows path traversal sequences to bypass directory restrictions. Combined with default anonymous unauthenticated access, this enables remote attackers to read arbitrary files on the underlying system. The vulnerability is network-accessible with low attack complexity and requires no privileges or user interaction.
Defensive priority
medium
Recommended defensive actions
- Apply vendor patches: update CSI Web Server to the most recent 1.x patch; for RTMC Pro 5 update to the most recent 5.x patch; for RTMC Pro 4 update to the most recent 4.x patch
- Contact Campbell Scientific for additional guidance if patching is not immediately feasible
- Review and restrict anonymous access configurations on CSI Web Server deployments
- Monitor access logs for unusual file retrieval patterns or traversal attempts
- Implement network segmentation to limit exposure of ICS web servers to untrusted networks
- Apply CISA ICS recommended practices for defense-in-depth security
- resourceLinkAnnotations: [source-item, ref-4, ref-6, ref-7, ref-8]
Evidence notes
CISA CSAF advisory ICSA-24-149-01 published 2024-05-28 identifies path traversal via crafted expression in file retrieval command. Anonymous unauthenticated access enabled by default. Affected products: CSI Web Server ≤1.6, RTMC Pro ≤5.0. CVSS 3.1 score 5.3 (MEDIUM).
Sources and references
Verified primary and authoritative sources
-
CVE-2024-5433 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-5433
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-5433 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-5433
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-149-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-149-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.