CVE-2013-10063: Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated attackers can exploit crafted GET requests to access arbitrary files outside the web root by injecting traversal sequences. This can expose sensitive system files and configuration data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-10063?
CVE-2013-10063 is rated as a medium severity vulnerability due to its potential for exposing sensitive files.
How do I fix CVE-2013-10063?
To fix CVE-2013-10063, upgrade the Netgear SPH200D Skype phone firmware to a version later than 1.0.4.80.
Who is affected by CVE-2013-10063?
CVE-2013-10063 affects users of the Netgear SPH200D Skype phone running firmware versions up to and including 1.0.4.80.
What type of attack does CVE-2013-10063 enable?
CVE-2013-10063 enables authenticated attackers to exploit path traversal vulnerabilities to access arbitrary files on the device.
What devices are impacted by CVE-2013-10063?
The vulnerability CVE-2013-10063 specifically impacts the Netgear SPH200D Skype phone.