HIGH · 8.8

CVE-2017-5260

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' accou...

Vulnerability Description

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuration file is accessible via direct object reference (DRO) at http://<device-ip-or-hostname>/goform/down_cfg_file by this otherwise low privilege 'user' account.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CambiumnetworksCnpilot R190V Firmware<= 4.3.2-r4
CambiumnetworksCnpilot R190V-
CambiumnetworksCnpilot E410 Firmware<= 4.3.2-r4
CambiumnetworksCnpilot E410-
CambiumnetworksCnpilot R190N Firmware<= 4.3.2-r4
CambiumnetworksCnpilot R190N-
CambiumnetworksCnpilot E400 Firmware<= 4.3.2-r4
CambiumnetworksCnpilot E400-
CambiumnetworksCnpilot E600 Firmware<= 4.3.2-r4
CambiumnetworksCnpilot E600-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-5260?

CVE-2017-5260 is a vulnerability with a CVSS score of 8.8 (HIGH). In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' accou...

How severe is CVE-2017-5260?

CVE-2017-5260 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-5260?

Check the references section above for vendor advisories and patch information. Affected products include: Cambiumnetworks Cnpilot R190V Firmware, Cambiumnetworks Cnpilot R190V, Cambiumnetworks Cnpilot E410 Firmware, Cambiumnetworks Cnpilot E410, Cambiumnetworks Cnpilot R190N Firmware.