NetDecision TFTP Server contains a flaw that allows a remote attacker to upload and retrieve files outside of the TFTP root path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (../../).
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Public
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.