CVE-2019-7404
An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.
Published:May 13, 2019
Last Modified:Nov 21, 2024
EPS:May 13, 2019
EPSS Score:0.00952
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Lg
Product
Gamp-7100
Lg
Gamp-7100
Vendor
Lg
Product
Gamp-7100 Firmware
Lg
Gamp-7100 Firmware
Vendor
Lg
Product
Gapm-7200
Lg
Gapm-7200
Vendor
Lg
Product
Gapm-7200 Firmware
Lg
Gapm-7200 Firmware
Vendor
Lg
Product
Gapm-8000
Lg
Gapm-8000
Vendor
Lg
Product
Gapm-8000 Firmware
Lg
Gapm-8000 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
