PT-2018-15337 · Arris · Arris Dg950A

Capitan Alfalo

·

Publicado

2018-12-23

·

Atualizado

2021-09-13

·

CVE-2018-20383

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ARRIS DG950A version 7.10.145 ARRIS DG950S version 7.10.145.EURO
Description The issue allows remote attackers to discover credentials via specific SNMP requests, including "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0".
Recommendations For ARRIS DG950A version 7.10.145, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation. For ARRIS DG950S version 7.10.145.EURO, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20383

Produtos afetados

Arris Dg950A