CVE-2017-9097

high-risk
Published 2017-06-16

In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.

Do I need to act?

~
9.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.1/10 Critical
NETWORK / LOW complexity

Affected Products (11)

Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb
Antiweb

Affected Vendors

58
/ 100
high-risk
Severity 31/34 · Critical
Exploitability 11/34 · Low
Exposure 16/34 · Moderate