ZeroHour

CVE-2018-10285

CVSS 3.0
9.8 critical
EPSS
13%p96
Published
()
Modified
Description

The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.

Vendors
ericssonlg
Products
ipecs nms
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.