10
CVE-2018-11541
- EPSS 0.28%
- Veröffentlicht 09.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to Build 485. It affects the SWe Lite devices 6.1.x up to Build 111 and 7.0.x up to Build 140.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ribboncommunications ≫ Sonus Sbc 1000 Firmware Version6.0.0
Ribboncommunications ≫ Sonus Sbc 1000 Firmware Version6.1.0
Ribboncommunications ≫ Sonus Sbc 1000 Firmware Version7.0.0
Ribboncommunications ≫ Sonus Sbc 2000 Firmware Version6.0.0
Ribboncommunications ≫ Sonus Sbc 2000 Firmware Version6.1.0
Ribboncommunications ≫ Sonus Sbc 2000 Firmware Version7.0.0
Ribboncommunications ≫ Sbc Swe Lite Web Version6.1.0
Ribboncommunications ≫ Sbc Swe Lite Web Version7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.514 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.