CVE-2018-10286
Last modified
CVE-2018-10286 is a vulnerability of currently unknown severity. The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.. EPSS estimates a 6.73% chance of exploitation in the next 30 days.
Description
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ericssonlg | Ipecs Nms | a.1ac |
References
- https://gist.github.com/berkgoksel/fde102503c457c0344e2e53b7971437aThird Party Advisory
- https://www.exploit-db.com/exploits/44515/Third Party Advisory, VDB Entry
- https://gist.github.com/berkgoksel/fde102503c457c0344e2e53b7971437aThird Party Advisory
- https://www.exploit-db.com/exploits/44515/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10286?
How severe is CVE-2018-10286?
How do I fix CVE-2018-10286?
Are you affected by CVE-2018-10286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
