HIGH · 7.5

CVE-2019-7404

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/...

Vulnerability Description

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LgGamp-7100 Firmware-
LgGamp-7100-
LgGapm-7200 Firmware-
LgGapm-7200-
LgGapm-8000 Firmware-
LgGapm-8000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-7404?

CVE-2019-7404 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/...

How severe is CVE-2019-7404?

CVE-2019-7404 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-7404?

Check the references section above for vendor advisories and patch information. Affected products include: Lg Gamp-7100 Firmware, Lg Gamp-7100, Lg Gapm-7200 Firmware, Lg Gapm-7200, Lg Gapm-8000 Firmware.