nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-15138 CVE-2018-15138
HIGHNuclei
ericssonlg ipecs_nms Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-15138 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ipecs_nmsBrowse ericssonlg / ipecs_nms | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBLG-Ericsson iPECS NMS 30M - Directory TraversalExploitDB exploitby Safak AslanNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHLG-Ericsson iPECS NMS 30M - Local File InclusionCVSS 7.5
Ericsson-LG iPECS NMS 30M allows local file inclusion via ipecs-cm/download?filename=../ URIs.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the target system, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cveericssonlfitraversaledbericssonlgvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:ericssonlg:ipecs_nms:30m-2.3gn:*:*:*:*:*:*:*
https://cxsecurity.com/issue/WLB-2018080070 https://www.exploit-db.com/exploits/45167/ https://nvd.nist.gov/vuln/detail/CVE-2018-15138 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
245167exploit
https://www.exploit-db.com/exploits/45167