9.8
CVE-2018-8859
- EPSS 0.31%
- Veröffentlicht 24.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:28
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Echelon ≫ Smartserver 1 Firmware Version-
Echelon ≫ Smartserver 2 Firmware Version < 4.11.007
Echelon ≫ I.Lon 100 Firmware Version-
Echelon ≫ I.Lon 600 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.538 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.