Vulnerability Description
Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with userName=admin in a cookie.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Top-Vision | Cc8800Ce Firmware | - |
| Top-Vision | Cc8800Ce | - |
Related Weaknesses (CWE)
References
- http://www.cnvd.org.cn/flaw/show/1420913Third Party AdvisoryVDB Entry
- https://github.com/pudding2/CC8800-CMTSThird Party Advisory
- http://www.cnvd.org.cn/flaw/show/1420913Third Party AdvisoryVDB Entry
- https://github.com/pudding2/CC8800-CMTSThird Party Advisory
FAQ
What is CVE-2018-18205?
CVE-2018-18205 is a vulnerability with a CVSS score of 7.5 (HIGH). Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with userName=admin in a cookie.
How severe is CVE-2018-18205?
CVE-2018-18205 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18205?
Check the references section above for vendor advisories and patch information. Affected products include: Top-Vision Cc8800Ce Firmware, Top-Vision Cc8800Ce.