CVE-2021-36717

Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:synerion:timenet:9.21:*:*:*:*:*:*:*

History

21 Nov 2024, 06:13

Type Values Removed Values Added
References () https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory () https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 5.4

16 Sep 2021, 11:15

Type Values Removed Values Added
Summary In order to perform a directory traversal attack, all an attacker needs is a web browser and some knowledge on where to blindly find any default files and directories on the system. on the "Name" parameter the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system. Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker can return to the root directory and open the host file. This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.

15 Sep 2021, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-22
References (CERT) https://www.gov.il/en/departments/faq/cve_advisories - (CERT) https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory
CPE cpe:2.3:a:synerion:timenet:9.21:*:*:*:*:*:*:*

07 Sep 2021, 12:45

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-07 12:15

Updated : 2024-11-21 06:13


NVD link : CVE-2021-36717

Mitre link : CVE-2021-36717

CVE.ORG link : CVE-2021-36717


JSON object : View

Products Affected

synerion

  • timenet
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')