CVE-2017-16787 EXPLOIT
6.5
MEDIUM · CVSS 3.0 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access.
Scoring
| CVSS | 6.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 6.62% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-12-15 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| meinbergglobal | lantime |
| meinbergglobal | lantime firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read | 2017-12-13 |
References
→ the Explorer · watch your stack · NVD