CVE-2017-8837
In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.94% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- peplink/b305hw2 firmware · peplink/380hw6 firmware · peplink/580hw2 firmware · peplink/710hw3 firmware · peplink/1350hw2 firmware · peplink/2500 firmware
- Source
- cve@mitre.org
References
- http://seclists.org/bugtraq/2017/Jun/1Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/42130/
- https://www.x41-dsec.de/lab/advisories/x41-2017-005-peplink/Patch, Third Party Advisory
- http://seclists.org/bugtraq/2017/Jun/1Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/42130/
- https://www.x41-dsec.de/lab/advisories/x41-2017-005-peplink/Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.