CVE-2019-25472: IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile
IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25472?
CVE-2019-25472 is considered a high severity vulnerability due to its potential to expose sensitive configuration files.
How do I fix CVE-2019-25472?
To mitigate CVE-2019-25472, it is recommended to update the IntelBras Telefone IP TIP200 or TIP200 LITE to the latest firmware version provided by the vendor.
What is the impact of CVE-2019-25472?
The impact of CVE-2019-25472 includes unauthorized access to potentially sensitive files, which could lead to further exploitation of the device.
Which devices are affected by CVE-2019-25472?
CVE-2019-25472 affects IntelBras Telefone IP TIP200 and TIP200 LITE devices.
Can CVE-2019-25472 be exploited remotely?
Yes, CVE-2019-25472 can be exploited remotely since it involves unauthenticated access through HTTP GET requests.