First published: Mon Dec 18 2017(Updated: )
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BrightSign OS | <=6.2.63 | |
BrightSign 4K242 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17739 is classified as a high severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2017-17739, update the BrightSign Digital Signage device firmware to version 6.2.64 or later.
CVE-2017-17739 affects BrightSign Digital Signage devices running firmware versions 6.2.63 and below.
Exploiting CVE-2017-17739 allows attackers to read or write files on the affected device, potentially leading to data leakage or system compromise.
CVE-2017-17739 is part of a series of vulnerabilities found in BrightSign devices, indicating a need for comprehensive security measures.