CVE
- Id
- 104060
- CVE No.
- CVE-2017-7240
- Status
- Candidate
- Description
- An issue was discovered on Miele Professional PG 8528 PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks. A Proof of Concept is GET /../../../../../../../../../../../../etc/shadow HTTP/1.1.
- Phase
- Assigned (20170323)
- Votes
- None (candidate not yet proposed)
- Comments