CVE-2020-9033: Path Traversal
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9033?
CVE-2020-9033 is a vulnerability found in Symmetricom SyncServer S100, S200, S250, S300, and S350 devices that allows Directory Traversal.
How does CVE-2020-9033 affect the Symmetricom SyncServer devices?
CVE-2020-9033 allows an attacker to perform Directory Traversal via the FileName parameter to authlog.php on affected Symmetricom SyncServer devices.
What is the severity of CVE-2020-9033?
CVE-2020-9033 has a severity rating of 6.5 (medium).
Which Symmetricom SyncServer devices are affected by CVE-2020-9033?
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices are affected by CVE-2020-9033.
How can I fix the CVE-2020-9033 vulnerability on my Symmetricom SyncServer device?
To fix the CVE-2020-9033 vulnerability, it is recommended to update your Symmetricom SyncServer device firmware to a version that does not have the vulnerability.