9.8

CVE-2017-8837

Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PeplinkB305hw2 Firmware Version7.0.1
   PeplinkBalance 305 Version-
Peplink380hw6 Firmware Version7.0.1
   PeplinkBalance 380 Version-
Peplink580hw2 Firmware Version7.0.1
   PeplinkBalance 580 Version-
Peplink710hw3 Firmware Version7.0.1
   PeplinkBalance 710 Version-
Peplink1350hw2 Firmware Version7.0.1
   PeplinkBalance 1350 Version-
Peplink2500 Firmware Version7.0.1
   PeplinkBalance 2500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.03% 0.931
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.