CVE-2017-7918 Information

Description

An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access control and may allow access to sensitive information and possibly allow for configuration changes.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Reference

http://www.securityfocus.com/bid/99083 https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

LOW

Base Score

LOW

Base Severity

6.8

Share on: