Record summary

CVE-2019-18922 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAllied Telesis AT-GS950/8 - Local File InclusionCVSS 7.5

Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 is susceptible to local file inclusion via its web interface.

Impact

Successful exploitation of this vulnerability allows an attacker to read arbitrary files on the affected device, leading to unauthorized access and potential data leakage.

Remediation

Apply the latest firmware update provided by Allied Telesis to fix the vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019packetstormseclistsalliedlfialliedtelesisvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:alliedtelesis:at-gs950\/8_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4