CVE-2018-16705
Last modified
CVE-2018-16705 is a vulnerability of currently unknown severity. FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.. EPSS estimates a 1.57% chance of exploitation in the next 30 days.
Description
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Furuno | Felcom 250 Firmware | All versions |
| Furuno | Felcom 500 Firmware | All versions |
References
- https://cyberskr.com/blog/furuno-felcom.htmlExploit, Technical Description, Third Party Advisory
- https://gist.github.com/CyberSKR/c00eabd6b1d5603d724b615ab358ff31Third Party Advisory
- https://cyberskr.com/blog/furuno-felcom.htmlExploit, Technical Description, Third Party Advisory
- https://gist.github.com/CyberSKR/c00eabd6b1d5603d724b615ab358ff31Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16705?
How severe is CVE-2018-16705?
How do I fix CVE-2018-16705?
Are you affected by CVE-2018-16705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
