ID

VAR-201710-0859


CVE

CVE-2017-15805


TITLE

Cisco Small Business SA520 and SA540 Path traversal vulnerability in device firmware

Trust: 0.8

sources: JVNDB: JVNDB-2017-009497

DESCRIPTION

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files. CiscoSmallBusinessSA520 and SA540 are firewall devices of Cisco Systems of the United States. An attacker could exploit this vulnerability to read arbitrary files with the \342\200\230thispage\342\200\231 parameter

Trust: 2.25

sources: NVD: CVE-2017-15805 // JVNDB: JVNDB-2017-009497 // CNVD: CNVD-2017-35152 // VULHUB: VHN-106664

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-35152

AFFECTED PRODUCTS

vendor:ciscomodel:small business sa520scope:eqversion:2.1.71

Trust: 2.4

vendor:ciscomodel:small business sa520scope:eqversion:2.2.0.7

Trust: 2.4

vendor:ciscomodel:small business sa540scope:eqversion:2.1.71

Trust: 2.4

vendor:ciscomodel:small business sa540scope:eqversion:2.2.0.7

Trust: 2.4

vendor:ciscomodel:small business sa520 and sa540 devicesscope:eqversion:2.1.71

Trust: 0.6

vendor:ciscomodel:small business sa520 and sa540 devicesscope:eqversion:2.2.0.7

Trust: 0.6

sources: CNVD: CNVD-2017-35152 // JVNDB: JVNDB-2017-009497 // CNNVD: CNNVD-201710-1074 // NVD: CVE-2017-15805

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15805
value: HIGH

Trust: 1.0

NVD: CVE-2017-15805
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-35152
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201710-1074
value: MEDIUM

Trust: 0.6

VULHUB: VHN-106664
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-15805
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-35152
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-106664
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15805
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-35152 // VULHUB: VHN-106664 // JVNDB: JVNDB-2017-009497 // CNNVD: CNNVD-201710-1074 // NVD: CVE-2017-15805

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-106664 // JVNDB: JVNDB-2017-009497 // NVD: CVE-2017-15805

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201710-1074

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-201710-1074

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009497

PATCH

title:Cisco SA540 Security Applianceurl:https://www.cisco.com/c/en/us/support/security/sa540-security-appliance/model.html

Trust: 0.8

title:Cisco SA520 Security Applianceurl:https://www.cisco.com/c/en/us/support/security/sa520-security-appliance/model.html

Trust: 0.8

sources: JVNDB: JVNDB-2017-009497

EXTERNAL IDS

db:NVDid:CVE-2017-15805

Trust: 3.1

db:JVNDBid:JVNDB-2017-009497

Trust: 0.8

db:CNNVDid:CNNVD-201710-1074

Trust: 0.7

db:CNVDid:CNVD-2017-35152

Trust: 0.6

db:NSFOCUSid:37861

Trust: 0.6

db:VULHUBid:VHN-106664

Trust: 0.1

sources: CNVD: CNVD-2017-35152 // VULHUB: VHN-106664 // JVNDB: JVNDB-2017-009497 // CNNVD: CNNVD-201710-1074 // NVD: CVE-2017-15805

REFERENCES

url:https://www.fwhibbit.es/lfi-en-cisco-small-business-sa500-series-cuando-la-seguridad-de-tu-red-esta-hecha-un-cisco

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2017-15805

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15805

Trust: 0.8

url:http://www.nsfocus.net/vulndb/37861

Trust: 0.6

sources: CNVD: CNVD-2017-35152 // VULHUB: VHN-106664 // JVNDB: JVNDB-2017-009497 // CNNVD: CNNVD-201710-1074 // NVD: CVE-2017-15805

SOURCES

db:CNVDid:CNVD-2017-35152
db:VULHUBid:VHN-106664
db:JVNDBid:JVNDB-2017-009497
db:CNNVDid:CNNVD-201710-1074
db:NVDid:CVE-2017-15805

LAST UPDATE DATE

2025-04-20T23:19:49.335000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-35152date:2017-11-27T00:00:00
db:VULHUBid:VHN-106664date:2017-11-08T00:00:00
db:JVNDBid:JVNDB-2017-009497date:2017-11-14T00:00:00
db:CNNVDid:CNNVD-201710-1074date:2017-10-27T00:00:00
db:NVDid:CVE-2017-15805date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-35152date:2017-11-27T00:00:00
db:VULHUBid:VHN-106664date:2017-10-23T00:00:00
db:JVNDBid:JVNDB-2017-009497date:2017-11-14T00:00:00
db:CNNVDid:CNNVD-201710-1074date:2017-10-27T00:00:00
db:NVDid:CVE-2017-15805date:2017-10-23T08:29:00.773