CVE-2018-10024
UnknownEPSS 1.43%
Last modified
CVE-2018-10024 is a vulnerability of currently unknown severity. ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ubiquoss | Vp5208a Firmware | All versions |
References
- https://www.tarlogic.com/advisories/Tarlogic-2018-002.txtThird Party Advisory
- https://www.tarlogic.com/advisories/Tarlogic-2018-002.txtThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10024?
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).
How severe is CVE-2018-10024?
Severity scoring for CVE-2018-10024 is pending analysis. The EPSS model estimates a 1.43% probability of exploitation in the next 30 days.
How do I fix CVE-2018-10024?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1002205DotNetZip.Semvered before 1.11.0 is vulnerable to directory …5.5
- CVE-2018-1002206SharpCompress before 0.21.0 is vulnerable to directory trave…
- CVE-2018-1002207mholt/archiver golang package before e4ef56d48eb029648b0e895…
- CVE-2018-1002208SharpZipLib before 1.0 RC1 is vulnerable to directory traver…5.5
- CVE-2018-1002209QuaZIP before 0.7.6 is vulnerable to directory traversal, al…
- CVE-2018-10023Catfish CMS V4.7.21 allows XSS via the pinglun parameter to …
- CVE-2018-10026The WeChat module in YzmCMS 3.7.1 has reflected XSS via the …
- CVE-2018-10027ESTsoft ALZip before 10.76 allows local users to execute arb…
- CVE-2018-10028joyplus-cms 1.6.0 allows remote attackers to obtain sensitiv…
- CVE-2018-10029CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin…
- CVE-2018-1003A buffer overflow vulnerability exists in the Microsoft JET …
- CVE-2018-10030CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/sitepref…
Are you affected by CVE-2018-10024?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
