CVE-2018-0677: OS Command Injection
Published Jan 9, 2019
·Updated
BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands via unspecified vectors.
Affected Software
2 affected components
Panasonic Bn-sdwbp3 Firmware<=1.0.9
Panasonic Bn-sdwbp3
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of BN-SDWBP3 firmware version 1.0.9 and earlier?
The vulnerability ID of BN-SDWBP3 firmware version 1.0.9 and earlier is CVE-2018-0677.
2
What is the severity of CVE-2018-0677?
The severity of CVE-2018-0677 is high with a CVSS score of 6.8.
3
How can an attacker exploit CVE-2018-0677?
An attacker with administrator rights on the same network segment can exploit CVE-2018-0677 to execute arbitrary OS commands via unspecified vectors.
4
Is Panasonic Bn-sdwbp3 firmware version 1.0.9 vulnerable?
Yes, Panasonic Bn-sdwbp3 firmware version 1.0.9 is vulnerable to CVE-2018-0677.
5
How can I fix CVE-2018-0677?
To fix CVE-2018-0677, upgrade BN-SDWBP3 firmware to version 1.1.0 or later.