Описание
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
Уязвимые конфигурации
Конфигурация 1Версия до 6.24.029 (исключая)Версия от 7.0.0 (включая) до 7.04.008 (исключая)
Одно из
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00379
Низкий
7.2 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-22
Связанные уязвимости
CVSS3: 7.2
github
около 2 лет назад
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
EPSS
Процентиль: 59%
0.00379
Низкий
7.2 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-22