CVE-2017-7237
SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.
El servidor Spiceworks TFTP, tal y como se distribuye con Spiceworks Inventory 7.5, permite a atacantes remotos acceder al directorio de Spiceworks data\configurations aprovechando la naturaleza no autenticada del servicio TFTP para todos los clientes que pueden llegar al puerto UDP 69, como lo demuestra una operación WRQ (también conocido como solicitud de escritura) para un archivo de configuración o un archivo ejecutable.
Spiceworks version 7.5 suffers from a TFTP improper access control file overwrite / upload vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-23 CVE Reserved
- 2017-04-05 CVE Published
- 2017-04-05 First Exploit
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/141934 | 2017-04-05 | |
https://www.exploit-db.com/exploits/41825 | 2024-08-05 | |
http://hyp3rlinx.altervista.org/advisories/SPICEWORKS-IMPROPER-ACCESS-CONTROL-FILE-OVERWRITE.txt | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.spiceworks.com/support/inventory/docs/network-config#security | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Spiceworks Search vendor "Spiceworks" | Spiceworks Search vendor "Spiceworks" for product "Spiceworks" | 7.5 Search vendor "Spiceworks" for product "Spiceworks" and version "7.5" | - |
Affected
|