Lucene search

K
nvd[email protected]NVD:CVE-2018-10577
HistoryMay 02, 2018 - 9:29 p.m.

CVE-2018-10577

2018-05-0221:29:00
CWE-434
web.nvd.nist.gov
2

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.8%

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.

Affected configurations

Nvd
Node
watchguardap200_firmwareRange<1.2.9.15
AND
watchguardap200Match-
Node
watchguardap102_firmwareRange<1.2.9.15
AND
watchguardap102Match-
Node
watchguardap100_firmwareRange<1.2.9.15
AND
watchguardap100Match-
Node
watchguardap300_firmwareRange<2.0.0.10
AND
watchguardap300Match-
VendorProductVersionCPE
watchguardap200_firmware*cpe:2.3:o:watchguard:ap200_firmware:*:*:*:*:*:*:*:*
watchguardap200-cpe:2.3:h:watchguard:ap200:-:*:*:*:*:*:*:*
watchguardap102_firmware*cpe:2.3:o:watchguard:ap102_firmware:*:*:*:*:*:*:*:*
watchguardap102-cpe:2.3:h:watchguard:ap102:-:*:*:*:*:*:*:*
watchguardap100_firmware*cpe:2.3:o:watchguard:ap100_firmware:*:*:*:*:*:*:*:*
watchguardap100-cpe:2.3:h:watchguard:ap100:-:*:*:*:*:*:*:*
watchguardap300_firmware*cpe:2.3:o:watchguard:ap300_firmware:*:*:*:*:*:*:*:*
watchguardap300-cpe:2.3:h:watchguard:ap300:-:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.8%