CVE-2017-16786

T

he Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:meinbergglobal:lantime_m100:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m1000:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m200:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m300:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m3000:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m400:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m500:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m600:-:*:*:*:*:*:*:*
cpe:2.3:h:meinbergglobal:lantime_m900:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:16

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/145388/Meinberg-LANTIME-Web-Configuration-Utility-6.16.008-Arbitrary-File-Read.html - Issue Tracking, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/145388/Meinberg-LANTIME-Web-Configuration-Utility-6.16.008-Arbitrary-File-Read.html - Issue Tracking, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2017/Dec/50 - Issue Tracking, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Dec/50 - Issue Tracking, Mailing List, Third Party Advisory

Information

Published : 2017-12-19 15:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-16786

Mitre link : CVE-2017-16786

CVE.ORG link : CVE-2017-16786


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor