CVE-2018-17935

HIGHCVSS 8.1/10EPSS 0.66%

Last modified

CVE-2018-17935 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Probability
0.66%

47.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TelecraneF25-2s Firmware< 00.0a
TelecraneF25-2d Firmware< 00.0a
TelecraneF25-4s Firmware< 00.0a
TelecraneF25-4d Firmware< 00.0a
TelecraneF25-6s Firmware< 00.0a
TelecraneF25-6d Firmware< 00.0a
TelecraneF25-8s Firmware< 00.0a
TelecraneF25-8d Firmware< 00.0a
TelecraneF25-10s Firmware< 00.0a
TelecraneF25-10d Firmware< 00.0a
TelecraneF25-60 Firmware< 00.0a

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17935?
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
How severe is CVE-2018-17935?
CVE-2018-17935 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17935?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17935?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST