7.5
CVSSv3

CVE-2017-7240

Published: 24/03/2017 Updated: 16/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks. A Proof of Concept is GET /../../../../../../../../../../../../etc/shadow HTTP/1.1. This affects PG8527 devices 2.02 prior to 2.12, PG8527 devices 2.51 prior to 2.61, PG8527 devices 2.52 prior to 2.62, PG8527 devices 2.54 prior to 2.64, PG8528 devices 2.02 prior to 2.12, PG8528 devices 2.51 prior to 2.61, PG8528 devices 2.52 prior to 2.62, PG8528 devices 2.54 prior to 2.64, PG8535 devices 1.00 prior to 1.10, PG8535 devices 1.04 prior to 1.14, PG8536 devices 1.10 prior to 1.20, and PG8536 devices 1.14 prior to 1.24.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

miele_professional pst10_webserver -

Exploits

Title: ====== Miele Professional PG 8528 - Web Server Directory Traversal Author: ======= Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co KG CVE-ID: ======= CVE-2017-7240 Risk Information: ================= Risk Factor: Medium CVSS Base Score: 50 CVSS Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N CVSS Temporal Vector: CVSS2#E:POC/RL:OF/ ...
The Miele Professional PG 8528 suffers from a directory traversal vulnerability ...

Recent Articles

New trends in the world of IoT threats
Securelist • Mikhail Kuzin Yaroslav Shmelev Vladimir Kuskov • 18 Sep 2018

Cybercriminals’ interest in IoT devices continues to grow: in H1 2018 we picked up three times as many malware samples attacking smart devices as in the whole of 2017. And in 2017 there were ten times more than in 2016. That doesn’t bode well for the years ahead. We decided to study what attack vectors are deployed by cybercriminals to infect smart devices, what malware is loaded into the system, and what it means for device owners and victims of freshly armed botnets. !function(e,t,n,s){var...

Dishwasher has directory traversal bug
The Register • Richard Chirgwin • 26 Mar 2017

Thanks a Miele-on for making everything dangerous, Internet of Things firmware slackers

Don't say you weren't warned: Miele went full Internet-of-Things with a network-connected dishwasher, gave it a web server, and now finds itself on the wrong end of a security bug report – and it's accused of ignoring the warning. The utterly predictable vulnerability advisory on the Full Disclosure mailing list details CVE-2017-7240 – aka "Miele Professional PG 8528 - Web Server Directory Traversal.” This is the builtin web server that's used to remotely control the glassware-cleaning mac...