First published: Mon Dec 18 2017(Updated: )
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BrightSign OS | <=6.2.63 | |
BrightSign 4K242 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17738 has been classified as a medium severity vulnerability due to its potential impact on file integrity.
To fix CVE-2017-17738, upgrade the BrightSign Digital Signage device firmware to version 6.2.64 or later.
CVE-2017-17738 affects the BrightSign 4K242 digital signage device running firmware versions 6.2.63 and below.
CVE-2017-17738 allows unauthorized renaming and modification of files through the /tools.html interface.
Yes, CVE-2017-17738 can be exploited remotely if the device is accessible from the internet.