7.5
CVSSv3

CVE-2019-18922

Published: 29/11/2019 Updated: 10/12/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated malicious users to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alliedtelesis at-gs950\\/8_firmware

Exploits

Allied Telesis AT-GS950/8 up until firmware AT-S107 version 113 [100047] suffers from a directory traversal vulnerability ...