vendor:
Secure Auditor
by:
John Page aka HYP3RLINX
7,5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Secure Auditor
Affected Version From: Secure Auditor v3.0
Affected Version To: Secure Auditor v3.0
Patch Exists: NO
Related CWE: CVE-2017-9024
CPE: a:secure_bytes:secure_auditor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Secure Auditor v3.0 / Cisco Config Manager TFTP Directory Traversal Exploit
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.
Mitigation:
No known mitigation or remediation for this vulnerability