CVE-2017-16787

MEDIUM

Meinberg LANTIME <6.24.004 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access.

Exploits (1)

exploitdb WORKING POC
by Jakub Palaczynski · textwebappscgi
https://www.exploit-db.com/exploits/43332

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Dec/33
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43332/

Scores

CVSS v3 6.5
EPSS 0.0919
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
meinbergglobal/lantime_firmware < 6.24.004
Published Dec 15, 2017
Tracked Since Feb 18, 2026