CVE-2020-9029: Path Traversal
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9029?
CVE-2020-9029 is a vulnerability in Symmetricom SyncServer S100, S200, S250, S300, and S350 devices that allows Directory Traversal via the FileName parameter to messagelog.php.
How severe is CVE-2020-9029?
CVE-2020-9029 has a severity rating of 6.5 out of 10, making it a medium-severity vulnerability.
Which devices are affected by CVE-2020-9029?
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices are affected by CVE-2020-9029.
How can the vulnerability be exploited?
CVE-2020-9029 can be exploited by performing Directory Traversal attacks through the FileName parameter in messagelog.php.
Is there a fix for CVE-2020-9029?
At the moment, there is no specific fix available for CVE-2020-9029. It is recommended to follow the vendor's security advisory for any updates or patches.