CVE-2017-16788: Path Traversal
Directory traversal vulnerability in the "Upload Groupkey" functionality in the Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with Admin-User access to write to arbitrary files and consequently gain root privileges by uploading a file, as demonstrated by storing a file in the cron.d directory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16788?
CVE-2017-16788 is a directory traversal vulnerability in the "Upload Groupkey" functionality in the Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004.
How does CVE-2017-16788 affect Meinberg LANTIME devices?
CVE-2017-16788 allows remote authenticated users with Admin-User access to write to arbitrary files and gain root privileges by uploading malicious files.
What is the severity of CVE-2017-16788?
CVE-2017-16788 has a severity rating of 7.2 (critical).
How can I fix CVE-2017-16788?
To fix CVE-2017-16788, update the Meinberg LANTIME firmware to version 6.24.004 or later.
Where can I find more information about CVE-2017-16788?
More information about CVE-2017-16788 can be found at http://seclists.org/fulldisclosure/2017/Dec/32.