Lucene search

K
cveMitreCVE-2018-18881
HistoryMar 21, 2019 - 4:00 p.m.

CVE-2018-18881

2019-03-2116:00:29
mitre
web.nvd.nist.gov
27
cve-2018-18881
denial of service
controlbyweb
x-320m-i
instrumentation-grade
data acquisition
nvd
firmware
network settings
tcp
physical factory reset

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.7%

A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.

Affected configurations

Nvd
Node
controlbywebx-320m-i_firmwareRange1.05
AND
controlbywebx-320m-iMatch-
VendorProductVersionCPE
controlbywebx-320m-i_firmware*cpe:2.3:o:controlbyweb:x-320m-i_firmware:*:*:*:*:*:*:*:*
controlbywebx-320m-i-cpe:2.3:h:controlbyweb:x-320m-i:-:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

28.7%

Related for CVE-2018-18881