PT-2018-15337 · Arris · Arris Dg950A

Capitan Alfalo

·

Published

2018-12-23

·

Updated

2021-09-13

·

CVE-2018-20383

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ARRIS DG950A version 7.10.145 ARRIS DG950S version 7.10.145.EURO
Description The issue allows remote attackers to discover credentials via specific SNMP requests, including "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0".
Recommendations For ARRIS DG950A version 7.10.145, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation. For ARRIS DG950S version 7.10.145.EURO, restrict access to the SNMP requests "iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0" and "iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0" to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20383

Affected Products

Arris Dg950A