ZeroHour

CVE-2018-16705

PoC
CVSS 3.0
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.

Vendors
furuno
Products
felcom 250 firmware, felcom 500 firmware
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.