Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16221

Опубликовано: 29 мая 2019
Источник: nvd
CVSS3: 8
CVSS2: 7.7
EPSS Низкий

Описание

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:yealink:ultra-elegant_ip_phone_sip-t41p_firmware:66.83.0.35:*:*:*:*:*:*:*
cpe:2.3:h:yealink:ultra-elegant_ip_phone_sip-t41p:-:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00696
Низкий

8 High

CVSS3

7.7 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
github
больше 3 лет назад

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).

EPSS

Процентиль: 71%
0.00696
Низкий

8 High

CVSS3

7.7 High

CVSS2

Дефекты

CWE-22