PatchSiren

Belden Hirschmann CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Belden Hirschmann CVE published 2017-02-13

CVE-2017-5163

CVE-2017-5163 is a path traversal weakness in Belden Hirschmann GECKO Lite Managed switch firmware. After an administrator downloads a configuration file, the device saves a copy in a location that can be reached without authentication. Because the saved copy contains password hashes, an attacker who can access the path may gain sensitive credential material. NVD lists affected firmware as version 2.0.00 [truncated]