PT-2018-15337 · Arris · Arris Dg950A
Capitan Alfalo
·
Published
2018-12-23
·
Updated
2021-09-13
·
CVE-2018-20383
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ARRIS DG950A version 7.10.145
ARRIS DG950S version 7.10.145.EURO
Description
The issue allows remote attackers to discover credentials via specific SNMP requests, including "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0".
Recommendations
For ARRIS DG950A version 7.10.145, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation.
For ARRIS DG950S version 7.10.145.EURO, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arris Dg950A