CVE-2017-9833: Path Traversal
DISPUTED /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9833?
CVE-2017-9833 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2017-9833?
To mitigate CVE-2017-9833, ensure that the Boa server is updated to a version that addresses this vulnerability.
What systems are affected by CVE-2017-9833?
CVE-2017-9833 affects devices running Boa version 0.94.14rc21, commonly integrated into specific camera systems.
Is CVE-2017-9833 a widely exploitable vulnerability?
CVE-2017-9833 is reported to be a system-integrator issue, which may limit its widespread exploitability.
What kind of attack is possible through CVE-2017-9833?
CVE-2017-9833 allows for directory traversal attacks, potentially enabling attackers to read sensitive files with root privileges.