HIGH
Directory traversal vulnerability in the "Upload Groupkey" functionality in the Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with Admin-User access to write to arbitrary files and consequently gain root privileges by uploading a file, as demonstrated by storing a file in the cron.d directory
Published Dec 15, 2017
7.2
HIGHCVSS 3.0
EPSS 4.00%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.