The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
References
Link | Resource |
---|---|
https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5 | Third Party Advisory |
https://helpdesk.airspan.com/browse/TRN3-1693 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
17 Aug 2022, 14:11
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://helpdesk.airspan.com/browse/TRN3-1693 - Permissions Required, Vendor Advisory | |
References | (MISC) https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5 - Third Party Advisory | |
CPE | cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:* cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
CWE | CWE-522 |
16 Aug 2022, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-16 01:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-36307
Mitre link : CVE-2022-36307
CVE.ORG link : CVE-2022-36307
JSON object : View
Products Affected
airspan
- airvelocity_1500_firmware
- airvelocity_1500
CWE
CWE-522
Insufficiently Protected Credentials