ZeroHour

CVE-2018-10024

CVSS 3.0
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).

Vendors
ubiquoss
Products
vp5208a firmware
Weakness
CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.