CVE-2019-3918: Critical severity nokia i-240w-q gpon ont vulnerability
Published Mar 5, 2019
·Updated
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
Affected Software
4 affected components
All of the following
Nokia I-240w-q Gpon Ont Firmware=3fe54567bozj19
Nokia I-240w-q Gpon Ont
Nokia I-240w-q Gpon Ont Firmware=3fe54567bozj19
Nokia I-240w-q Gpon Ont
Event History
Mar 5, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-3918?
CVE-2019-3918 has a high severity rating due to the presence of hard coded credentials.
2
How do I fix CVE-2019-3918?
To fix CVE-2019-3918, update the firmware of the Alcatel Lucent I-240W-Q GPON ONT to a version without hard coded credentials.
3
What devices are affected by CVE-2019-3918?
CVE-2019-3918 affects the Alcatel Lucent I-240W-Q GPON ONT running firmware version 3FE54567BOZJ19.
4
What are the implications of CVE-2019-3918?
CVE-2019-3918 allows unauthorized access to the Telnet and SSH interfaces, which can lead to further exploitation.
5
Is there a workaround for CVE-2019-3918?
There is no known workaround for CVE-2019-3918; upgrading the firmware is the recommended approach.