Vulnerabilities > CVE-2017-17738 - Unspecified vulnerability in Brightsign 4K242 Firmware 6.2.63
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
Hardware | 1 |
Exploit-Db
description | BrightSign Digital Signage - Multiple Vulnerablities. CVE-2017-17737,CVE-2017-17738,CVE-2017-17739. Webapps exploit for Hardware platform |
file | exploits/hardware/webapps/43364.txt |
id | EDB-ID:43364 |
last seen | 2017-12-19 |
modified | 2017-12-19 |
platform | hardware |
port | |
published | 2017-12-19 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43364/ |
title | BrightSign Digital Signage - Multiple Vulnerablities |
type | webapps |
Packetstorm
data source | https://packetstormsecurity.com/files/download/145489/brightsignds-xsstraversalupload.txt |
id | PACKETSTORM:145489 |
last seen | 2017-12-19 |
published | 2017-12-19 |
reporter | singularitysec |
source | https://packetstormsecurity.com/files/145489/BrightSign-Digital-Signage-XSS-Traversal-File-Upload.html |
title | BrightSign Digital Signage XSS / Traversal / File Upload |