CVE-2017-9024

Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.
Configurations

Configuration 1 (hide)

cpe:2.3:a:secure-bytes:secure_cisco_auditor:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:35

Type Values Removed Values Added
References () http://hyp3rlinx.altervista.org/advisories/SECURE-AUDITOR-v3.0-DIRECTORY-TRAVERSAL.txt - Exploit, Third Party Advisory () http://hyp3rlinx.altervista.org/advisories/SECURE-AUDITOR-v3.0-DIRECTORY-TRAVERSAL.txt - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/42041/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/42041/ - Exploit, Third Party Advisory, VDB Entry

09 Sep 2021, 17:22

Type Values Removed Values Added
CPE cpe:2.3:a:secure_bytes:secure_cisco_auditor:3.0:*:*:*:*:*:*:* cpe:2.3:a:secure-bytes:secure_cisco_auditor:3.0:*:*:*:*:*:*:*

Information

Published : 2017-05-21 14:29

Updated : 2024-11-21 03:35


NVD link : CVE-2017-9024

Mitre link : CVE-2017-9024

CVE.ORG link : CVE-2017-9024


JSON object : View

Products Affected

secure-bytes

  • secure_cisco_auditor
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')