Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.
References
Link | Resource |
---|---|
http://hyp3rlinx.altervista.org/advisories/SECURE-AUDITOR-v3.0-DIRECTORY-TRAVERSAL.txt | Exploit Third Party Advisory |
https://www.exploit-db.com/exploits/42041/ | Exploit Third Party Advisory VDB Entry |
http://hyp3rlinx.altervista.org/advisories/SECURE-AUDITOR-v3.0-DIRECTORY-TRAVERSAL.txt | Exploit Third Party Advisory |
https://www.exploit-db.com/exploits/42041/ | Exploit Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://hyp3rlinx.altervista.org/advisories/SECURE-AUDITOR-v3.0-DIRECTORY-TRAVERSAL.txt - Exploit, Third Party Advisory | |
References | () https://www.exploit-db.com/exploits/42041/ - Exploit, Third Party Advisory, VDB Entry |
09 Sep 2021, 17:22
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:secure-bytes:secure_cisco_auditor:3.0:*:*:*:*:*:*:* |
Information
Published : 2017-05-21 14:29
Updated : 2024-11-21 03:35
NVD link : CVE-2017-9024
Mitre link : CVE-2017-9024
CVE.ORG link : CVE-2017-9024
JSON object : View
Products Affected
secure-bytes
- secure_cisco_auditor
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')