packetstormsecurity.com
http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html CVE-2018-14916
CRITICALNuclei
Loytec LGATE-902 <6.4.2 - Local File Inclusion
Record summary
CVE-2018-14916 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALLoytec LGATE-902 <6.4.2 - Local File InclusionCVSS 9.1
Loytec LGATE-902 versions prior to 6.4.2 suffers from a local file inclusion vulnerability.
Impact
An attacker can exploit this vulnerability to read sensitive files on the device.
Remediation
Upgrade the Loytec LGATE-902 device to version 6.4.2 or later to mitigate the vulnerability.
WeaknessesCWE-732
Authors0x_Akoko
Template tagscve2018cveloyteclfipacketstormseclistsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:h:loytec:lgate-902:-:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html https://nvd.nist.gov/vuln/detail/CVE-2018-14916 http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html https://seclists.org/fulldisclosure/2019/Apr/12 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
420190409 Loytec LGATE-902: Multiple Vulnerabilities (XSS, Path traversal and File Deletion)mailing list
http://seclists.org/fulldisclosure/2019/Apr/12 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-14916 20190407 Loytec LGATE-902: Multiple Vulnerabilities (XSS, Path traversal and File Deletion)mailing list
https://seclists.org/fulldisclosure/2019/Apr/12