CVE-2021-33903 Information
Jun 07, 2022
cve
Description
In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices changing the password of the root user via the CLI does not change the password of the root user for SNMPv3 access. (However changing the password of the root user via LANconfig does change the password of the root user for SNMPv3 access.)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.nmedv.de/wp-content/uploads/2021/10/NME-2021-001.txt
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: