CVE-2017-9833 describes a path traversal vulnerability in Boa web server version 0.94.14rc21, specifically within the /cgi-bin/wapopen component, allowing an attacker to read arbitrary files with root privileges by injecting "../.." via the FILECAMERA GET variable. This vulnerability is rated as High severity (CVSS 7.5) due to its network-based attack vector, low complexity, and high impact on confidentiality. While the Boa project itself states this is a system integrator issue, exploit intelligence indicates active exploitation, with Nuclei templates and an ExploitDB entry available. The vulnerability has garnered significant community discussion and media coverage, including reports of its use in attacks against energy organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.94.14.21CPE matchmatch criteria | cpe:2.3:a:boa:boa:0.94.14.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.