Vulnerability CVE-2018-16705


Published: 2018-09-10

Description:
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Furuno -> Felcom 250 firmware 
Furuno -> Felcom 500 firmware 

 References:
https://cyberskr.com/blog/furuno-felcom.html
https://gist.github.com/CyberSKR/c00eabd6b1d5603d724b615ab358ff31

Copyright 2024, cxsecurity.com

 

Back to Top