Lucene search

K
cveMitreCVE-2017-9833
HistoryJun 24, 2017 - 2:29 a.m.

CVE-2017-9833

2017-06-2402:29:00
CWE-22
mitre
web.nvd.nist.gov
107
In Wild
2
boa
0.94.14rc21
vulnerability
injection
filecamera
cgi-bin
wapopen
root access
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.735

Percentile

98.1%

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of “…/…” using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

Affected configurations

Nvd
Node
boaboaMatch0.94.14.21
VendorProductVersionCPE
boaboa0.94.14.21cpe:2.3:a:boa:boa:0.94.14.21:*:*:*:*:*:*:*

Social References

More

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.735

Percentile

98.1%