VulnerabilityModified
CVE-2022-36307
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.
MEDIUM 6.8EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- airspan/airvelocity 1500 firmware
- Source
- cve-assign@fb.com
References
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5Third Party Advisory
- https://helpdesk.airspan.com/browse/TRN3-1693Permissions Required, Vendor Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8j75-qh6c-wpc5Third Party Advisory
- https://helpdesk.airspan.com/browse/TRN3-1693Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.