imPC@ndo IT

Tracker / CVE-2017-15805

CVE-2017-15805

High 7.5

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

Affected products and versions

cisco small_business_sa520_firmware
cisco small_business_sa540_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References