CVE-2021-46902

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2024
Last modified:
17/06/2025

Description

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:* 6.24.029 (excluding)
cpe:2.3:o:meinbergglobal:lantime_firmware:*:*:*:*:*:*:*:* 7.0.0 (including) 7.04.008 (excluding)