CVE-2017-5260 Vulnerability Details

  /     /     /  

CVE-2017-5260 Metadata Quick Info

CVE Published: 20/12/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: rapid7 | Vendor: Cambium Networks | Product: cnPilot
Status : PUBLISHED

CVE-2017-5260 Description

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the \'user\' account, the configuration file is accessible via direct object reference (DRO) at http:///goform/down_cfg_file by this otherwise low privilege \'user\' account.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-472
CWE Name: CWE-472 (External Control of Assumed-Immutable Web Parameter)
Source: Cambium Networks

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).