6.8

CVE-2017-16786

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MeinbergglobalLantime Firmware Version <= 6.24.003
   MeinbergglobalLantime M100 Version-
   MeinbergglobalLantime M1000 Version-
   MeinbergglobalLantime M200 Version-
   MeinbergglobalLantime M300 Version-
   MeinbergglobalLantime M3000 Version-
   MeinbergglobalLantime M400 Version-
   MeinbergglobalLantime M500 Version-
   MeinbergglobalLantime M600 Version-
   MeinbergglobalLantime M900 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.531
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.