PT-2020-16701 · Basetech · Basetech Ge-131
Roman
·
Published
2020-11-17
·
Updated
2020-12-01
·
CVE-2020-27553
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BASETech GE-131 BT-1837836 firmware version 20180921
Description
The web-server in the system is configured with the option "DocumentRoot /etc", allowing an attacker with network access to download any files from the "/etc" folder without authentication. This issue can be exploited without the need for path traversal sequences, enabling unauthenticated remote attackers to gain access to sensitive information.
Recommendations
For BASETech GE-131 BT-1837836 firmware version 20180921, consider reconfiguring the web-server to restrict access to sensitive files in the "/etc" folder, or apply alternative security measures to prevent unauthorized file downloads until a patch is available.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Basetech Ge-131