CVE-2017-16786
19.12.2017, 15:29
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.Enginsight
Vendor | Product | Version |
---|---|---|
meinbergglobal | lantime_firmware | 𝑥 ≤ 6.24.003 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References