Vulnerability Details CVE-2015-2166
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.736
EPSS Ranking 98.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2015-2166
-
cpe:2.3:a:ericsson:drutt_mobile_service_delivery_platform:4.0
-
cpe:2.3:a:ericsson:drutt_mobile_service_delivery_platform:5.0
-
cpe:2.3:a:ericsson:drutt_mobile_service_delivery_platform:6.0