CVE-2017-5168
HIGHHanwha Techwin Smart Security Manager <1.5 - Path Traversal
Title source: llmDescription
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing specific HTTP requests, if a user visits a malicious page, an attacker can gain access to arbitrary files on the server. Smart Security Manager Versions 1.4 and prior to 1.31 are affected by these vulnerabilities. These vulnerabilities can allow for remote code execution.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/96147
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-040-01
Scores
CVSS v3
7.5
EPSS
0.0362
EPSS Percentile
88.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (2)
hanwha-security/smart_security_manager
< 1.5
n/a/Hanwha Techwin Smart Security Manager Versions 1.5 and prior
Hanwha Techwin Smart Security Manager Versions 1.5 and prior
Published
Feb 13, 2017
Tracked Since
Feb 18, 2026