// For flags

CVE-2017-15805

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

Los dispositivos Cisco Small Business SA520 y SA540 con firmware 2.1.71 y 2.2.0.7 permiten el salto de directorio ../ en scgi-bin/platform.cgi mediante el parámetro thispage para leer archivos arbitrarios.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-10-23 CVE Reserved
  • 2017-10-23 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Small Business Sa520 Firmware
Search vendor "Cisco" for product "Small Business Sa520 Firmware"
2.1.71
Search vendor "Cisco" for product "Small Business Sa520 Firmware" and version "2.1.71"
-
Affected
in Cisco
Search vendor "Cisco"
Small Business Sa520
Search vendor "Cisco" for product "Small Business Sa520"
--
Safe
Cisco
Search vendor "Cisco"
Small Business Sa520 Firmware
Search vendor "Cisco" for product "Small Business Sa520 Firmware"
2.2.0.7
Search vendor "Cisco" for product "Small Business Sa520 Firmware" and version "2.2.0.7"
-
Affected
in Cisco
Search vendor "Cisco"
Small Business Sa520
Search vendor "Cisco" for product "Small Business Sa520"
--
Safe
Cisco
Search vendor "Cisco"
Small Business Sa540 Firmware
Search vendor "Cisco" for product "Small Business Sa540 Firmware"
2.1.71
Search vendor "Cisco" for product "Small Business Sa540 Firmware" and version "2.1.71"
-
Affected
in Cisco
Search vendor "Cisco"
Small Business Sa540
Search vendor "Cisco" for product "Small Business Sa540"
--
Safe
Cisco
Search vendor "Cisco"
Small Business Sa540 Firmware
Search vendor "Cisco" for product "Small Business Sa540 Firmware"
2.2.0.7
Search vendor "Cisco" for product "Small Business Sa540 Firmware" and version "2.2.0.7"
-
Affected
in Cisco
Search vendor "Cisco"
Small Business Sa540
Search vendor "Cisco" for product "Small Business Sa540"
--
Safe