10
CVE-2018-18473
- EPSS 7%
- Veröffentlicht 21.03.2019 16:00:28
- Zuletzt bearbeitet 21.11.2024 03:55:59
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Patlite ≫ Nbm-d88n Firmware Version-
Patlite ≫ Nhl-3fb1 Firmware Version-
Patlite ≫ Nhl-3fv1n Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7% | 0.906 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.