CVE-2018-19648: Critical severity adtran pmaa vulnerability
Published Mar 27, 2019
·Updated
An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile over RESTCONF.
Affected Software
2 affected components
Adtran PMAA=1.6.2
Adtran PMAA=1.6.3
Event History
Mar 27, 2019
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19648?
CVE-2018-19648 has a medium severity level, allowing unprivileged users to create privileged accounts.
2
How do I fix CVE-2018-19648?
To fix CVE-2018-19648, update the ADTRAN PMAA software to version 1.6.5 or later.
3
What versions of ADTRAN PMAA are affected by CVE-2018-19648?
CVE-2018-19648 affects ADTRAN PMAA versions 1.6.2, 1.6.3, and 1.6.4.
4
What type of access does CVE-2018-19648 exploit?
CVE-2018-19648 exploits NETCONF Access Management to allow unauthorized privilege escalation.
5
Can CVE-2018-19648 lead to arbitrary command execution?
Yes, CVE-2018-19648 enables unprivileged users to execute arbitrary commands on affected systems.