Directory Traversal Vulnerability in Cisco Small Business SA520 and SA540 Devices
CVE-2017-15805
7.5HIGH
What is CVE-2017-15805?
Cisco Small Business SA520 and SA540 devices running firmware versions 2.1.71 and 2.2.0.7 are vulnerable to a directory traversal attack through the 'thispage' parameter in the scgi-bin/platform.cgi file. This flaw allows an attacker to read arbitrary files on the server, potentially exposing sensitive information. Proper security measures and firmware updates are essential to mitigate such vulnerabilities.