6.5
CVSSv3

CVE-2017-16787

Published: 15/12/2017 Updated: 29/12/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Web Configuration Utility in Meinberg LANTIME devices with firmware prior to 6.24.004 allows remote malicious users to read arbitrary files by leveraging failure to restrict URL access.

Vulnerable Product Search on Vulmon Subscribe to Product

meinbergglobal lantime_firmware

Exploits

Title: Meinberg LANTIME Web Configuration Utility - Arbitrary File Read Author: Jakub Palaczynski CVE: CVE-2017-16787 Exploit tested on: ================== Meinberg LANTIME Web Configuration Utility 616008 Vulnerability affects: ====================== All LTOS6 firmware releases before 624004 Vulnerability: ************** Arbitrary File ...
Meinberg LANTIME Web Configuration Utility version 616008 suffers from an arbitrary file read vulnerability ...
Meinberg LANTIME Web Configuration Utility version 616008 suffers from an authentication bypass vulnerability ...