CVE-2017-16786
EUVD-2017-796419.12.2017, 15:29
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| meinbergglobal | lantime_firmware | 𝑥 ≤ 6.24.003 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References