Vulnerability CVE-2017-7922


Published: 2017-06-21

Description:
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.

Type:

CWE-269

(Improper Privilege Management)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Cambium networks -> Epmp 1000 hotspot firmware 
Cambium networks -> Epmp 1000 firmware 
Cambium networks -> Epmp elevate firmware 
Cambium networks -> Epmp 2000 firmware 

 References:
http://www.securityfocus.com/bid/99083
https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01

Copyright 2024, cxsecurity.com

 

Back to Top