CVE-2018-4062
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can activate snmpd without any configuration changes to trigger this vulnerability.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.32% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- sierrawireless/airlink es450 firmware
- Source
- talos-cna@cisco.com
References
- http://packetstormsecurity.com/files/152647/Sierra-Wireless-AirLink-ES450-SNMPD-Hard-Coded-Credentials.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108147Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0747Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/152647/Sierra-Wireless-AirLink-ES450-SNMPD-Hard-Coded-Credentials.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108147Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03Third Party Advisory, VDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0747Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.