HIGH · 8.1

CVE-2018-17935

All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of a...

Vulnerability Description

All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TelecraneF25-2S Firmware< 00.0a
TelecraneF25-2S-
TelecraneF25-2D Firmware< 00.0a
TelecraneF25-2D-
TelecraneF25-4S Firmware< 00.0a
TelecraneF25-4S-
TelecraneF25-4D Firmware< 00.0a
TelecraneF25-4D-
TelecraneF25-6S Firmware< 00.0a
TelecraneF25-6S-
TelecraneF25-6D Firmware< 00.0a
TelecraneF25-6D-
TelecraneF25-8S Firmware< 00.0a
TelecraneF25-8S-
TelecraneF25-8D Firmware< 00.0a
TelecraneF25-8D-
TelecraneF25-10S Firmware< 00.0a
TelecraneF25-10S-
TelecraneF25-10D Firmware< 00.0a
TelecraneF25-10D-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-17935?

CVE-2018-17935 is a vulnerability with a CVSS score of 8.1 (HIGH). All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of a...

How severe is CVE-2018-17935?

CVE-2018-17935 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-17935?

Check the references section above for vendor advisories and patch information. Affected products include: Telecrane F25-2S Firmware, Telecrane F25-2S, Telecrane F25-2D Firmware, Telecrane F25-2D, Telecrane F25-4S Firmware.