First published: Thu Jan 11 2018(Updated: )
Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot dot forward slash) before a file name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsemi S350i Firmware | =2.70.15 | |
Microsemi S350i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-5068 is high, with a severity value of 7.5.
The affected software is Symmetricom s350i 2.70.15.
The vulnerability in CVE-2014-5068 allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability in the web application.
The CWE ID of CVE-2014-5068 is 22.
You can find more information about CVE-2014-5068 at https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-5068/.