CVE-2017-10931 Vulnerability Details

  /     /     /  

CVE-2017-10931 Metadata Quick Info

CVE Published: 19/09/2017 | CVE Updated: 17/09/2024 | CVE Year: 2017
Source: zte | Vendor: ZTE | Product: ZX10 1800-2S
Status : PUBLISHED

CVE-2017-10931 Description

The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Path Traversal
Source: ZTE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).