ZeroHour

CVE-2018-8859

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.

Vendors
echelon
Products
smartserver 1 firmware, smartserver 2 firmware, i.lon 100 firmware, i.lon 600 firmware
Weakness
CWE-288, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.