Vulnerability Description
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sierrawireless | Airlink Es450 Firmware | 4.9.3 |
| Sierrawireless | Airlink Es450 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152647/Sierra-Wireless-AirLink-ES450-SNMPD-ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108147Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party AdvisoryVDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0747ExploitThird Party Advisory
- http://packetstormsecurity.com/files/152647/Sierra-Wireless-AirLink-ES450-SNMPD-ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/108147Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party AdvisoryVDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0747ExploitThird Party Advisory
FAQ
What is CVE-2018-4062?
CVE-2018-4062 is a vulnerability with a CVSS score of 8.1 (HIGH). A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded cred...
How severe is CVE-2018-4062?
CVE-2018-4062 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-4062?
Check the references section above for vendor advisories and patch information. Affected products include: Sierrawireless Airlink Es450 Firmware, Sierrawireless Airlink Es450.