CVE-2013-5756: Path Traversal
Published Aug 3, 2014
·Updated
Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx.
Affected Software
1 affected component
Yealink SIP-T38G
Event History
Aug 3, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5756?
CVE-2013-5756 has a medium severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2013-5756?
To mitigate CVE-2013-5756, ensure your Yealink SIP-T38G firmware is updated to the latest version provided by the vendor.
3
Who is affected by CVE-2013-5756?
CVE-2013-5756 affects remote authenticated users of the Yealink SIP-T38G VoIP phone.
4
What type of vulnerability is CVE-2013-5756?
CVE-2013-5756 is identified as a directory traversal vulnerability.
5
What can an attacker do with CVE-2013-5756?
An attacker exploiting CVE-2013-5756 can read arbitrary files on the server by manipulating the page parameter.