8.8
CVE-2018-0676
- EPSS 0.16%
- Veröffentlicht 09.01.2019 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:43
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Panasonic ≫ Bn-sdwbp3 Firmware Version <= 1.0.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.337 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5.8 | 6.5 | 6.4 |
AV:A/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.