Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-7237. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This advisory describes an improper access control vulnerability in Spiceworks TFTP Server (CVE-2017-7237), allowing unauthenticated remote attackers to overwrite or upload arbitrary files to the 'data\configurations' directory via UDP port 69. The proof-of-concept demonstrates file overwrite and arbitrary file upload using TFTP commands.
Description
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.
Exploits (1)
This advisory describes an improper access control vulnerability in Spiceworks TFTP Server (CVE-2017-7237), allowing unauthenticated remote attackers to overwrite or upload arbitrary files to the 'data\configurations' directory via UDP port 69. The proof-of-concept demonstrates file overwrite and arbitrary file upload using TFTP commands.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H