9.8

CVE-2017-7318

Exploit
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siklu ≫ Etherhaul Firmware Version <= 7.3.0
   Siklu ≫ Etherhaul-5500fd Version -
   Siklu ≫ Etherhaul 500tx Version -
   Siklu ≫ Etherhaul 60ghz V-band Radio Version -
   Siklu ≫ Etherhaul 70ghz E-band Radio Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.85% 0.893
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blog.iancaling.com/post/155127766533/
Third Party Advisory
Exploit
http://www.securityfocus.com/bid/97227
Third Party Advisory
VDB Entry