CVE-2018-16705 Information
Feb 14, 2021
cve
Description
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system’s usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes as well as the SMS server password in cleartext.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://cyberskr.com/blog/furuno-felcom.html https://gist.github.com/CyberSKR/c00eabd6b1d5603d724b615ab358ff31
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: