PT-2022-23303 · Airspan · Airspan Airvelocity 1500
Vladionescu
·
Published
2022-08-16
·
Updated
2022-08-17
·
CVE-2022-36308
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Airspan AirVelocity 1500 versions prior to 15.18.00.2511
Description
The web management UI of the affected software displays SNMP credentials in plaintext and stores SNMPv3 credentials unhashed on the filesystem. This allows anyone with web access to use these credentials to manipulate the eNodeB over SNMP. The issue may also affect other AirVelocity and AirSpeed models.
Recommendations
For versions prior to 15.18.00.2511, update to version 15.18.00.2511 or later to resolve the issue. As a temporary workaround, consider restricting web access to the management UI to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Airspan Airvelocity 1500