CVE-2017-5168

HIGH

Hanwha Techwin Smart Security Manager <1.5 - Path Traversal

Title source: llm
STIX 2.1

Description

An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing specific HTTP requests, if a user visits a malicious page, an attacker can gain access to arbitrary files on the server. Smart Security Manager Versions 1.4 and prior to 1.31 are affected by these vulnerabilities. These vulnerabilities can allow for remote code execution.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96147
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-040-01

Scores

CVSS v3 7.5
EPSS 0.0362
EPSS Percentile 88.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
hanwha-security/smart_security_manager < 1.5
n/a/Hanwha Techwin Smart Security Manager Versions 1.5 and prior Hanwha Techwin Smart Security Manager Versions 1.5 and prior
Published Feb 13, 2017
Tracked Since Feb 18, 2026