CVE-2014-5068: Path Traversal
Published Jan 11, 2018
·Updated
Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot dot forward slash) before a file name.
Affected Software
2 affected components
Microsemi S350i Firmware=2.70.15
Microsemi S350i
Event History
Jan 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5068?
The severity of CVE-2014-5068 is high, with a severity value of 7.5.
2
What is the affected software of CVE-2014-5068?
The affected software is Symmetricom s350i 2.70.15.
3
How does the vulnerability in CVE-2014-5068 allow remote attackers to read arbitrary files?
The vulnerability in CVE-2014-5068 allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability in the web application.
4
What is the CWE ID of CVE-2014-5068?
The CWE ID of CVE-2014-5068 is 22.
5
Where can I find more information about CVE-2014-5068?
You can find more information about CVE-2014-5068 at https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-5068/.