ZeroHour

CVE-2018-20385

PoC
CVSS 3.0
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Vendors
castlenet
Products
cbv38z4ec firmware, cbv38z4ecnit firmware, cbw383g4j firmware, cbw38g4j firmware
Weakness
CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.