Path Traversal Vulnerability in Belden Hirschmann GECKO Lite Managed Switch
CVE-2017-5163
5.9MEDIUM
What is CVE-2017-5163?
A path traversal vulnerability exists in the Belden Hirschmann GECKO Lite Managed Switch, where an administrator may inadvertently expose sensitive configuration files containing user password hashes. This occurs when the system saves a copy of the configuration file to an accessible location after being downloaded, allowing unauthorized access without authentication. Such vulnerabilities can lead to potential exploitation by attackers seeking to gain unauthorized access to user credentials stored within these configuration files.
Affected Version(s)
Belden Hirschmann GECKO 2.0.00 and prior Belden Hirschmann GECKO 2.0.00 and prior
