Описание
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.
Ссылки
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.3.0.01249 (включая) до 15.18.00.2511 (включая)
Одновременно
cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00953
Низкий
8.8 High
CVSS3
Дефекты
CWE-242
NVD-CWE-noinfo
EPSS
Процентиль: 76%
0.00953
Низкий
8.8 High
CVSS3
Дефекты
CWE-242
NVD-CWE-noinfo