Directory Traversal Vulnerability in Symmetricom SyncServer Devices
CVE-2020-9030

6.5MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
17 February 2020

What is CVE-2020-9030?

Certain Symmetricom SyncServer devices are susceptible to a Directory Traversal vulnerability through the FileName parameter in the syslog.php file. This flaw could potentially allow attackers to gain unauthorized access to sensitive files within the system, leading to data exposure and compromise of the device’s integrity. Users of affected SyncServer models are advised to apply security patches and monitor for unusual activity.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-9030 : Directory Traversal Vulnerability in Symmetricom SyncServer Devices