PT-2020-16701 · Basetech · Basetech Ge-131

Roman

·

Published

2020-11-17

·

Updated

2020-12-01

·

CVE-2020-27553

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BASETech GE-131 BT-1837836 firmware version 20180921
Description The web-server in the system is configured with the option "DocumentRoot /etc", allowing an attacker with network access to download any files from the "/etc" folder without authentication. This issue can be exploited without the need for path traversal sequences, enabling unauthenticated remote attackers to gain access to sensitive information.
Recommendations For BASETech GE-131 BT-1837836 firmware version 20180921, consider reconfiguring the web-server to restrict access to sensitive files in the "/etc" folder, or apply alternative security measures to prevent unauthorized file downloads until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27553

Affected Products

Basetech Ge-131