PT-2023-9805 · Draytek · Draytek Vigor2960
Tmotfl
·
Published
2023-03-03
·
Updated
2024-08-02
·
CVE-2023-1163
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DrayTek Vigor 2960 versions 1.5.1.4 through 1.5.1.5
Description
A critical vulnerability has been found in the Web Management Interface of DrayTek Vigor 2960, specifically in the function
getSyslogFile of the file mainfunction.cgi. The issue is related to incorrect restriction of directory path names, which can lead to path traversal. This allows a remote attacker to gain unauthorized access to confidential system files. The exploit has been disclosed to the public and may be used.Recommendations
For DrayTek Vigor 2960 versions 1.5.1.4 through 1.5.1.5, consider disabling the
getSyslogFile function of the mainfunction.cgi file as a temporary workaround to minimize the risk of exploitation. Restrict access to the Web Management Interface to reduce the attack surface.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Draytek Vigor2960