CVE-2017-8075: Critical severity TP-Link Tl-sg108e Firmware vulnerability
Published Apr 23, 2017
·Updated
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
Affected Software
4 affected components
TP-Link Tl-sg108e Firmware=1.1.2
TP-Link TL-SG108E
All of the following
TP-Link Tl-sg108e Firmware=1.1.2
TP-Link TL-SG108E
Event History
Apr 23, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-8075?
CVE-2017-8075 has a medium severity rating as it allows remote attackers to retrieve credentials in cleartext.
2
How do I fix CVE-2017-8075?
To fix CVE-2017-8075, upgrade the firmware of the TP-Link TL-SG108E device to a version later than 1.1.2.
3
What type of devices are affected by CVE-2017-8075?
CVE-2017-8075 affects the TP-Link TL-SG108E with firmware version 1.1.2.
4
What specific information can be retrieved due to CVE-2017-8075?
CVE-2017-8075 allows attackers to retrieve sensitive credentials from the 'Switch Info' log lines.
5
Can CVE-2017-8075 be exploited locally?
CVE-2017-8075 is a remote vulnerability, meaning it does not require local access for exploitation.