PT-2017-17994 · Cambium Networks · Epmp

Published

2017-06-21

·

Updated

2019-10-09

·

CVE-2017-7918

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cambium Networks ePMP (affected versions not specified)
Description An issue with improper access control was found, allowing an attacker to remotely trigger device configuration backups after a valid user has used SNMP configuration export. These backups lack proper access control, potentially allowing access to sensitive information and possibly enabling configuration changes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7918

Affected Products

Epmp