6.8

CVE-2017-16786

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Meinbergglobal ≫ Lantime Firmware Version <= 6.24.003
   Meinbergglobal ≫ Lantime M100 Version -
   Meinbergglobal ≫ Lantime M1000 Version -
   Meinbergglobal ≫ Lantime M200 Version -
   Meinbergglobal ≫ Lantime M300 Version -
   Meinbergglobal ≫ Lantime M3000 Version -
   Meinbergglobal ≫ Lantime M400 Version -
   Meinbergglobal ≫ Lantime M500 Version -
   Meinbergglobal ≫ Lantime M600 Version -
   Meinbergglobal ≫ Lantime M900 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.01% 0.783
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 6.8 8 6.9
AV:N/AC:L/Au:S/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://packetstormsecurity.com/files/145388/Meinberg-LANTIME-Web-Configuration-Utility-6.16.008-Arbitrary-File-Read.html
Third Party Advisory
VDB Entry
Issue Tracking
http://seclists.org/fulldisclosure/2017/Dec/50
Third Party Advisory
Mailing List
Issue Tracking