CVE-2017-7922
Last modified
CVE-2017-7922 is a vulnerability of currently unknown severity. An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.. EPSS estimates a 9.64% chance of exploitation in the next 30 days.
Description
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cambium Networks | Epmp 1000 Firmware | All versions |
| Cambium Networks | Epmp Elevate Firmware | All versions |
| Cambium Networks | Epmp 2000 Firmware | All versions |
| Cambium Networks | Epmp 1000 Hotspot Firmware | All versions |
References
- http://www.securityfocus.com/bid/99083Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/99083Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-17-166-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7922?
How severe is CVE-2017-7922?
How do I fix CVE-2017-7922?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7916A Permissions, Privileges, and Access Controls issue was dis…
- CVE-2017-7917A Cross-Site Request Forgery issue was discovered in Moxa On…
- CVE-2017-7918An Improper Access Control issue was discovered in Cambium N…
- CVE-2017-7919An Improper Authentication issue was discovered in Newport X…
- CVE-2017-7920An Improper Authentication issue was discovered in ABB VSN30…
- CVE-2017-7921An Improper Authentication issue was discovered in Hikvision…9.8
- CVE-2017-7923A Password in Configuration File issue was discovered in Hik…
- CVE-2017-7924An Improper Input Validation issue was discovered in Rockwel…
- CVE-2017-7925A Password in Configuration File issue was discovered in Dah…
- CVE-2017-7926A Cross-Site Request Forgery issue was discovered in OSIsoft…
- CVE-2017-7927A Use of Password Hash Instead of Password for Authenticatio…
- CVE-2017-7928An Improper Access Control issue was discovered in Schweitze…
Are you affected by CVE-2017-7922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
