CVE-2017-17746 - CERT CVE
ID CVE-2017-17746
Sažetak Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies to the IP address of the NAT gateway, and any user behind that NAT gateway is also treated as authenticated.
Reference
CVSS
Base: 7.7
Impact: 10.0
Exploitability:5.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:A/AC:L/Au:S/C:C/I:C/A:C
Zadnje važnije ažuriranje 03-10-2019 - 00:03
Objavljeno 20-12-2017 - 20:29