Vulnerability Description
The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Commscope | Arris Tg2492Lg-Na Firmware | 061213 |
| Commscope | Arris Tg2492Lg-Na | - |
Related Weaknesses (CWE)
References
- http://misteralfa-hack.blogspot.com/2018/09/arris-tg2492lg-na-cable-modem-gatewaExploitTechnical DescriptionThird Party Advisory
- http://misteralfa-hack.blogspot.com/2018/09/arris-tg2492lg-na-cable-modem-gatewaExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-17555?
CVE-2018-17555 is a vulnerability with a CVSS score of 7.5 (HIGH). The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter.
How severe is CVE-2018-17555?
CVE-2018-17555 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17555?
Check the references section above for vendor advisories and patch information. Affected products include: Commscope Arris Tg2492Lg-Na Firmware, Commscope Arris Tg2492Lg-Na.