CVE-2020-9032: Path Traversal
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9032?
CVE-2020-9032 is a vulnerability that affects Symmetricom SyncServer S100, S200, S250, S300, and S350 devices.
How does CVE-2020-9032 impact Symmetricom SyncServer devices?
CVE-2020-9032 allows Directory Traversal via the FileName parameter to kernlog.php, potentially enabling an attacker to access files outside of the intended directory.
What is the severity of CVE-2020-9032?
CVE-2020-9032 has a severity rating of 6.5 out of 10, indicating a medium-severity vulnerability.
Which versions of Symmetricom SyncServer devices are vulnerable to CVE-2020-9032?
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices are vulnerable to CVE-2020-9032.
How can I mitigate the vulnerability CVE-2020-9032?
To mitigate CVE-2020-9032, it is recommended to apply the latest firmware updates provided by Microchip for the affected SyncServer devices.