CVE-2020-9030: Path Traversal
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9030?
CVE-2020-9030 is a vulnerability in Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices that allows Directory Traversal via the FileName parameter to the syslog.php.
What is the severity of CVE-2020-9030?
CVE-2020-9030 has a severity level of medium with a score of 6.5.
Which devices are affected by CVE-2020-9030?
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 are affected by CVE-2020-9030.
How can CVE-2020-9030 be exploited?
CVE-2020-9030 can be exploited through Directory Traversal via the FileName parameter to the syslog.php file.
Is there a fix for CVE-2020-9030?
At the moment, there is no known fix for CVE-2020-9030. It is recommended to follow the vendor's security advisory for updates and patches.