Vulnerability Name: | CVE-2018-16195 (CCN-154298) | ||||||||||||
Assigned: | 2018-12-14 | ||||||||||||
Published: | 2018-12-14 | ||||||||||||
Updated: | 2019-01-17 | ||||||||||||
Summary: | Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 8.3 High (CVSS v2 Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-16195 Source: CCN Type: JVN#87535892 Multiple vulnerabilities in Aterm WF1200CR and Aterm WG1200CR Source: CCN Type: Aterm Web site Aterm WF1200CR and Aterm WG1200CR Source: XF Type: UNKNOWN aterm-cve201816195-cmd-exec(154298) Source: MISC Type: Vendor Advisory https://jpn.nec.com/security-info/secinfo/nv18-021.html Source: JVN Type: Third Party Advisory JVN#87535892 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |