CVE-2017-9097
Summary
| CVE | CVE-2017-9097 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-16 03:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file. |
Risk And Classification
Primary CVSS: v3.0 9.1 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-22 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.1 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hoytech | Antiweb | 3.0.7 | hms2 | All | All |
| Application | Hoytech | Antiweb | 3.3.5 | All | All | All |
| Application | Hoytech | Antiweb | 3.6.1 | All | All | All |
| Application | Hoytech | Antiweb | 3.7.1 | All | All | All |
| Application | Hoytech | Antiweb | 3.7.2 | All | All | All |
| Application | Hoytech | Antiweb | 3.8.1 | All | All | All |
| Application | Hoytech | Antiweb | 3.8.2 | All | All | All |
| Application | Hoytech | Antiweb | 3.8.3 | All | All | All |
| Application | Hoytech | Antiweb | 3.8.4 | All | All | All |
| Application | Hoytech | Antiweb | 3.8.5 | All | All | All |
| Application | Hoytech | Antiweb | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.netbiter.com/docs/default-source/netbiter-english/software/hms-security-ad... | af854a3a-2127-422b-91ae-364da2661108 | www.netbiter.com | Patch, Vendor Advisory |
| Capitan Alfa | af854a3a-2127-422b-91ae-364da2661108 | misteralfa-hack.blogspot.cl | Mailing List, Third Party Advisory |
| Page not found · GitHub · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.