PT-2022-8586 · Telos · Telos Z/Ip One
David Parillo
·
Published
2022-01-24
·
Updated
2022-01-28
·
CVE-2020-17383
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Telos Z/IP One versions through 4.0.0r
Description
A directory traversal issue allows an unauthenticated individual to gain root level access to the device's file system. This access can be used to identify configuration settings, password hashes for built-in accounts, and the cleartext password for remote configuration of the device through the WebUI.
Recommendations
For versions through 4.0.0r, consider restricting access to the WebUI to minimize the risk of exploitation until a patch is available.
As a temporary workaround, limit the use of remote configuration features to reduce the attack surface.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telos Z/Ip One