First published: Wed Jul 25 2018(Updated: )
LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leading to discovery of a password hash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LICA miniCMTS E8K | ||
Lica miniCMTS E8K Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14083 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2018-14083, update the Lica miniCMTS E8K firmware to the latest version that addresses this vulnerability.
CVE-2018-14083 can be exploited through remote attacks that use crafted POST requests to access sensitive files.
CVE-2018-14083 allows attackers to obtain the password hash from the inc/user.ini file.
Not all versions are vulnerable; only certain firmware versions of Lica miniCMTS E8K are affected by CVE-2018-14083.