CVE-2017-16759: Path Traversal
Published Nov 9, 2017
·Updated
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
Affected Software
2 affected componentsFixes available
composer/librenms/librenms<2017-08-18
2017-08-18
librenms librenms<=1.30
Remediation
Event History
Nov 9, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 13, 2022
Advisory Published
01:44 AM
Frequently Asked Questions
1
What is CVE-2017-16759?
CVE-2017-16759 is a vulnerability in the installation process of LibreNMS before 2017-08-18 that allows remote attackers to read arbitrary files.
2
How can remote attackers exploit CVE-2017-16759?
Remote attackers can exploit CVE-2017-16759 by manipulating the installation process in LibreNMS to read arbitrary files.
3
What is the severity of CVE-2017-16759?
CVE-2017-16759 has a severity rating of medium with a CVSS score of 5.9.
4
How do I determine if I am affected by CVE-2017-16759?
You are affected by CVE-2017-16759 if you are using a version of LibreNMS before 2017-08-18 or if you are using LibreNMS version 1.30.
5
How do I fix CVE-2017-16759?
To fix CVE-2017-16759, update your LibreNMS installation to version 2017-08-18 or later.