← Voltar para CVEs
CVE-2018-20385
N/ADescricao
CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado12/23/2018
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
castlenet:cbv38z4eccastlenet:cbv38z4ec_firmwarecastlenet:cbv38z4ecnitcastlenet:cbv38z4ecnit_firmwarecastlenet:cbw383g4jcastlenet:cbw383g4j_firmwarecastlenet:cbw38g4jcastlenet:cbw38g4j_firmware
Fraquezas (CWE)
CWE-522
Referencias
https://misteralfa-hack.blogspot.com/2018/12/stringbleed-y-ahora-que-passwords-leaks.html(cve@mitre.org)
https://github.com/ezelf/sensitivesOids/blob/master/oidpassswordleaks.csv(af854a3a-2127-422b-91ae-364da2661108)
https://misteralfa-hack.blogspot.com/2018/12/stringbleed-y-ahora-que-passwords-leaks.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.