PT-2017-14560 · Meinberg · Meinberg Lantime

Jakub Palaczynski

·

Published

2017-12-15

·

Updated

2017-12-29

·

CVE-2017-16787

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Meinberg LANTIME devices with firmware prior to 6.24.004
Description The issue allows remote attackers to read arbitrary files due to a failure in restricting URL access in the Web Configuration Utility.
Recommendations For firmware versions prior to 6.24.004, update the firmware to version 6.24.004 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16787

Affected Products

Meinberg Lantime