Vulnerability Description
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Small Business Sa520 Firmware | 2.1.71 |
| Cisco | Small Business Sa520 | - |
| Cisco | Small Business Sa540 Firmware | 2.1.71 |
| Cisco | Small Business Sa540 | - |
Related Weaknesses (CWE)
References
- https://www.fwhibbit.es/lfi-en-cisco-small-business-sa500-series-cuando-la-segurThird Party Advisory
- https://www.fwhibbit.es/lfi-en-cisco-small-business-sa500-series-cuando-la-segurThird Party Advisory
FAQ
What is CVE-2017-15805?
CVE-2017-15805 is a vulnerability with a CVSS score of 7.5 (HIGH). Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
How severe is CVE-2017-15805?
CVE-2017-15805 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15805?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Small Business Sa520 Firmware, Cisco Small Business Sa520, Cisco Small Business Sa540 Firmware, Cisco Small Business Sa540.