10

CVE-2018-16591

Exploit
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FurunoFelcom 250 Firmware Version-
   FurunoFelcom 250 Version-
FurunoFelcom 500 Firmware Version-
   FurunoFelcom 500 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.16% 0.799
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://cyberskr.com/blog/furuno-felcom.html
Third Party Advisory
Exploit
Technical Description
https://gist.github.com/CyberSKR/2c30d964d48b5e1518ded88bd953b710
Third Party Advisory