Vulnerability CVE-2018-12072


Published: 2018-06-17

Description:
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can completely compromise it.

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cloudmedia -> Popcorn a-200 firmware 

 References:
https://gist.github.com/freetom/2a446a226d0e98807c8b0c1111ef2def

Copyright 2024, cxsecurity.com

 

Back to Top