First published: Sat Jun 24 2017(Updated: )
** DISPUTED ** /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Boa Boa | =0.94.14.21 | |
=0.94.14.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9833 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
To mitigate CVE-2017-9833, ensure that the Boa server is updated to a version that addresses this vulnerability.
CVE-2017-9833 affects devices running Boa version 0.94.14rc21, commonly integrated into specific camera systems.
CVE-2017-9833 is reported to be a system-integrator issue, which may limit its widespread exploitability.
CVE-2017-9833 allows for directory traversal attacks, potentially enabling attackers to read sensitive files with root privileges.