In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path traversal in the image-relocator module.CreditsKürşat ÇetinReferenceshttps://www.s-can.at/en/the-new-monitool-v4-2-security-first/