CVE-2019-18922
Allied Telesis AT-GS950/8 - Local File Inclusion
Record summary
CVE-2019-18922 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAllied Telesis AT-GS950/8 - Local File InclusionCVSS 7.5
Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 is susceptible to local file inclusion via its web interface.
Impact
Successful exploitation of this vulnerability allows an attacker to read arbitrary files on the affected device, leading to unauthorized access and potential data leakage.
Remediation
Apply the latest firmware update provided by Allied Telesis to fix the vulnerability.
Source: ProjectDiscovery