PT-2019-15715 · Allied Telesis · At-Gs950/8
Dr. H. Benda
+1
·
Published
2019-11-29
·
Updated
2020-02-06
·
CVE-2019-18922
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Allied Telesis AT-GS950/8 versions prior to Firmware AT-S107 V.1.1.3 [1.00.047]
Description
A Directory Traversal issue in the Web interface allows unauthenticated attackers to read arbitrary system files via a GET request. This issue affects an End-of-Life product.
Recommendations
For Allied Telesis AT-GS950/8 versions prior to Firmware AT-S107 V.1.1.3 [1.00.047], update to Firmware AT-S107 V.1.1.3 [1.00.047] or later to resolve the issue. As a temporary workaround, consider restricting access to the Web interface until a patch is applied.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
At-Gs950/8