vendor:
DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway
by:
An independent security researcher
9,8
CVSS
CRITICAL
Arbitrary File Disclosure
200
CWE
Product Name: DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2017-11502
CPE: h:cisco:dpc3928ad_docsisdocsis_3.0_2-port_voice_gateway
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2017
Arbitrary File Disclosure Vulnerability in Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway
An attacker can get the /etc/passwd file from the remote device, by sending a GET request to the TCP/4321 port of the Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway.
Mitigation:
Contact the vendor for a patch or upgrade to a newer version of the product.