PT-2024-10551 · Unknown · Tftp Server+1

Modpr0Be

+2

·

Published

2024-06-21

·

Updated

2024-09-15

·

CVE-2012-6664

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Distinct Intranet Servers versions 3.10 and earlier
Description The issue allows remote attackers to read or write arbitrary files via a .. (dot dot) in the (1) get or (2) put commands. This is due to multiple directory traversal vulnerabilities in the TFTP Server.
Recommendations For Distinct Intranet Servers versions 3.10 and earlier, consider restricting access to the TFTP Server until a patch is available. As a temporary workaround, avoid using the get and put commands with .. (dot dot) sequences to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2012-6664

Affected Products

Distinct Intranet Servers
Tftp Server