CVE-2019-7387
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from system/maintenance/export.php, it accepts the path provided by the user, leading to path traversal via the name parameter.
Affected (3)
Products: Systrome: Isg 600c Firmware, Isg 600h Firmware, Isg 800w Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1-r2.1_trunk-20180914 |
| Running on/with | Platform Versions |
|---|---|
Systrome Isg 600c | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1-r2.1_trunk-20180914 |
| Running on/with | Platform Versions |
|---|---|
Systrome Isg 600h | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1-r2.1_trunk-20180914 |
| Running on/with | Platform Versions |
|---|---|
Systrome Isg 800w | All versions |
References (4)
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.