ZeroHour

CVE-2017-8837

CVSS 3.0
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.

Vendors
peplink
Products
b305hw2 firmware, 380hw6 firmware, 580hw2 firmware, 710hw3 firmware, 1350hw2 firmware, 2500 firmware
Weakness
CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.