PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-5433 Campbell Scientific CVE debrief

A path traversal vulnerability in Campbell Scientific CSI Web Server allows unauthenticated remote attackers to access files outside the webserver root directory. The vulnerability exists in a command that returns the most recent file matching a given expression; when combined with a specially crafted expression, this permits directory traversal. Anonymous access is enabled by default, exposing affected systems to unauthorized file access without authentication. The vulnerability affects CSI Web Server versions ≤1.6 and RTMC Pro versions ≤5.0. CISA published advisory ICSA-24-149-01 on May 28, 2024, coordinating with Campbell Scientific on remediation.

Vendor
Campbell Scientific
Product
RTMC Pro
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-28
Original CVE updated
2024-05-28
Advisory published
2024-05-28
Advisory updated
2024-05-28

Who should care

Organizations operating Campbell Scientific data acquisition systems in industrial, environmental, or research environments; OT security teams managing remote monitoring infrastructure; asset owners with publicly accessible CSI Web Server deployments.

Technical summary

The CSI Web Server implements a command to retrieve the most recent file matching a specified expression. Insufficient input validation on this expression parameter allows path traversal sequences to bypass directory restrictions. Combined with default anonymous unauthenticated access, this enables remote attackers to read arbitrary files on the underlying system. The vulnerability is network-accessible with low attack complexity and requires no privileges or user interaction.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor patches: update CSI Web Server to the most recent 1.x patch; for RTMC Pro 5 update to the most recent 5.x patch; for RTMC Pro 4 update to the most recent 4.x patch
  • Contact Campbell Scientific for additional guidance if patching is not immediately feasible
  • Review and restrict anonymous access configurations on CSI Web Server deployments
  • Monitor access logs for unusual file retrieval patterns or traversal attempts
  • Implement network segmentation to limit exposure of ICS web servers to untrusted networks
  • Apply CISA ICS recommended practices for defense-in-depth security
  • resourceLinkAnnotations: [source-item, ref-4, ref-6, ref-7, ref-8]

Evidence notes

CISA CSAF advisory ICSA-24-149-01 published 2024-05-28 identifies path traversal via crafted expression in file retrieval command. Anonymous unauthenticated access enabled by default. Affected products: CSI Web Server ≤1.6, RTMC Pro ≤5.0. CVSS 3.1 score 5.3 (MEDIUM).

Sources and references

Verified primary and authoritative sources

  • CVE-2024-5433 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-5433

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-5433 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-5433

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-149-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-149-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.