Lucene search

K
cve[email protected]CVE-2022-36308
HistoryAug 16, 2022 - 1:15 a.m.

CVE-2022-36308

2022-08-1601:15:13
CWE-522
CWE-256
web.nvd.nist.gov
36
5
airspan
airvelocity
snmp
plaintext credentials
unhashed credentials
snmpv3
nvd
cve-2022-36308

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.0%

Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affect other AirVelocity and AirSpeed models.

Affected configurations

NVD
Node
airspanairvelocity_1500_firmwareRange9.3.0.01249–15.18.00.2511
AND
airspanairvelocity_1500Match-

CNA Affected

[
  {
    "product": "AirVelocity",
    "vendor": "Airspan",
    "versions": [
      {
        "lessThan": "15.18.00.2511",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.0%

Related for CVE-2022-36308