Vulnerability CVE-2017-7918


Published: 2017-06-21

Description:
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access control and may allow access to sensitive information and possibly allow for configuration changes.

Type:

CWE-269

(Improper Privilege Management)

CVSS2 => (AV:N/AC:M/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6/10
6.4/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Cambium networks -> Epmp 1000 hotspot firmware 
Cambium networks -> Epmp 1000 firmware 
Cambium networks -> Epmp elevate firmware 
Cambium networks -> Epmp 2000 firmware 

 References:
http://www.securityfocus.com/bid/99083
https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01

Copyright 2024, cxsecurity.com

 

Back to Top