Vulnerability Name: | CVE-2017-17746 (CCN-136656) | ||||||||||||
Assigned: | 2017-12-19 | ||||||||||||
Published: | 2017-12-19 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies to the IP address of the NAT gateway, and any user behind that NAT gateway is also treated as authenticated. | ||||||||||||
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 6.0 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 7.7 High (CVSS v2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-306 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-17746 Source: CCN Type: Full-Disclosure Mailing List, Tue, 19 Dec 2017 12:39:38 +1030 Multiple Vulnerabilities in TP-Link TL-SG108E - CVE-2017-17745, CVE-2017-17746, CVE-2017-17747 Source: FULLDISC Type: Exploit, Mailing List, Mitigation, Third Party Advisory 20171219 Multiple Vulnerabilities in TP-Link TL-SG108E - CVE-2017-17745, CVE-2017-17746, CVE-2017-17747 Source: XF Type: UNKNOWN tplink-cve201717746-info-disc(136656) Source: CCN Type: Packet Storm Security [12-20-2017] TP-Link TL-SG108E XSS / Weak Access Control Source: CCN Type: TP-Link Web site TP-Link: WiFi Networking Equipment for Home & Business | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |