Vulnerability record · CVE-2017-6527 · published 9 March 2017
CVE-2017-6527: dnaLIMS directory traversal in viewAppletFsa.cgi seqID parameter
Dnatools · Dnalims
dnaTools dnaLIMS 4-2015s13 is vulnerable to a NUL-terminated directory traversal attack via the seqID parameter of viewAppletFsa.cgi. An unauthenticated attacker can read system files accessible to the web server user, exposing configuration, credential or other sensitive data. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.
Description
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network path traversal with high confidentiality impact, public exploit code and very high EPSS, though not in KEV and no confirmed active campaigns.
What it is
dnaTools dnaLIMS 4-2015s13 is vulnerable to a NUL-terminated directory traversal attack via the seqID parameter of viewAppletFsa.cgi. An unauthenticated attacker can read system files accessible to the web server user, exposing configuration, credential or other sensitive data. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.
Impact
An attacker gains read access to any file the web server user can read, which may include application configuration, credentials or operating system files. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through the viewAppletFsa.cgi endpoint by manipulating the seqID parameter; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).
Exploitation
Public exploit code exists (Exploit-DB 41578 and a vendor advisory tagged Exploit), and EPSS is 0.56647 (99th percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.
What to do
- Apply the vendor fix or upgrade dnaLIMS past version 4-2015s13 if available; no patched version is stated in the record.
- Restrict network access to viewAppletFsa.cgi and the dnaLIMS web interface to trusted networks or a VPN.
- Run the web server under a low-privilege account with minimal filesystem read permissions.
- Deploy a WAF or input validation rule that rejects traversal sequences and NUL bytes in the seqID parameter.
- Audit the web server user's file permissions and remove access to sensitive system files.
Detection
- Monitor web logs for requests to viewAppletFsa.cgi with seqID values containing ../, ..\, %00 or encoded traversal sequences.
- Alert on HTTP responses from viewAppletFsa.cgi returning files outside the expected application directory or unusually large responses.
- Review file access logs for the web server user reading /etc/passwd, configuration files or other sensitive paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96823 | |
| https://www.exploit-db.com/exploits/41578/ | |
| https://www.shorebreaksecurity.com/blog/product-security-advisory-psa0002-dnalims/ | ExploitTechnical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/96823 | |
| https://www.exploit-db.com/exploits/41578/ | |
| https://www.shorebreaksecurity.com/blog/product-security-advisory-psa0002-dnalims/ | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2017-6527 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6527), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.