9.8

CVE-2018-20380

Exploit
Ambit DDW2600 5.100.1009, DDW2602 5.105.1003, T60C926 4.64.1012, and U10C019 5.66.1026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubeeinteractive ≫ Ambit Ddw2600 Firmware Version 5.100.1009
   Ubeeinteractive ≫ Ambit Ddw2600 Version -
Ubeeinteractive ≫ Ambit Ddw2602 Firmware Version 5.105.1003
   Ubeeinteractive ≫ Ambit Ddw2602 Version -
Ubeeinteractive ≫ Ambit T60c926 Firmware Version 4.64.1012
   Ubeeinteractive ≫ Ambit T60c926 Version -
Ubeeinteractive ≫ Ambit U10c019 Firmware Version 5.66.1026
   Ubeeinteractive ≫ Ambit U10c019 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.6% 0.726
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/ezelf/sensitivesOids/blob/master/oidpassswordleaks.csv
Third Party Advisory
https://misteralfa-hack.blogspot.com/2018/12/stringbleed-y-ahora-que-passwords-leaks.html
Third Party Advisory
Exploit