Directory Traversal Vulnerability in Symmetricom SyncServer Products
CVE-2020-9031

6.5MEDIUM

Key Information:

Vendor

Microchip

Vendor
CVE Published:
17 February 2020

What is CVE-2020-9031?

Certain models of the Symmetricom SyncServer, including the S100, S200, S250, S300, and S350, are impacted by a directory traversal vulnerability that affects the 'FileName' parameter in the daemonlog.php script. This security flaw could allow unauthorized access to the file system, potentially exposing sensitive information or leading to further exploitation. It is important for users to evaluate their current versions and apply necessary updates to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-9031 : Directory Traversal Vulnerability in Symmetricom SyncServer Products