First published: Sun Dec 23 2018(Updated: )
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Commscope Arris Dg950a Firmware | =7.10.145 | |
Commscope Arris Dg950a | =3.0 | |
Arris Dg950s Firmware | =7.10.145.euro | |
Commscope Arris Dg950s | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20383 is critical with a severity value of 9.8.
You can discover credentials in ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices by using iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices are affected by CVE-2018-20383.
To fix CVE-2018-20383, it is recommended to apply the latest firmware update provided by Commscope or Arris.
Commscope Arris Dg950a and Arris Dg950s are vulnerable to CVE-2018-20383 if they are running the affected firmware versions.