Vulnerability Details CVE-2017-15805
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-15805
-
cpe:2.3:h:cisco:small_business_sa520:-
-
cpe:2.3:h:cisco:small_business_sa540:-
-
cpe:2.3:o:cisco:small_business_sa520_firmware:2.1.71
-
cpe:2.3:o:cisco:small_business_sa520_firmware:2.2.0.7
-
cpe:2.3:o:cisco:small_business_sa540_firmware:2.1.71
-
cpe:2.3:o:cisco:small_business_sa540_firmware:2.2.0.7