7.5
CVSSv3

CVE-2017-9833

Published: 24/06/2017 Updated: 17/05/2024
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

boa boa 0.94.14.21

Exploits

BOA Web Server 09414 - Access to arbitrary files as privileges Title: Vulnerability in BOA Webserver 09414 Date: 20-06-2017 Status: Vendor contacted, patch available Scope: Arbitrary file access Platforms: Unix Author: Miguel Mendez Z Vendor Homepage: wwwboaorg Version: Boa Webserver 09414rc21 CVE: CVE-2017-9833 Vulnerability desc ...
BOA Web Server version 09414rc21 an arbitrary file access vulnerability ...

Github Repositories

CVE-2017-9833 POC

CVE-2017-9833 Reference: wwwcvedetailscom/cve/CVE-2017-9833/ Shodan dork: product:"Boa Web Server" 09414rc21 Payload: /cgi-bin/wapopen/?FILECAMERA=//etc/shadow POC:

Recent Articles

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks
The Register

Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Flaws in the open-source tool exploited – and India's power grid was a target

Microsoft is warning that systems using the long-discontinued Boa web server could be at risk of attacks after a series of intrusion attempts of power grid operations in India likely included exploiting security flaws in the technology. Researchers with Microsoft's Security Threat Intelligence unit examined an April report from cybersecurity company Recorded Future about the intrusion efforts into India's power grid dating back to 2020 and, more recently, into a national emergency response syste...