CVE-2017-17739
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.
Affected (1)
Products: Brightsign: 4k242 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.2.63 |
| Running on/with | Platform Versions |
|---|---|
Brightsign 4k242 | All versions |
References (4)
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party AdvisoryVDB Entry
Timeline
No history available yet.