CVE-2017-5137
MEDIUMSendQuick Entera/Avera <2HF16 - Info Disclosure
Title source: llmDescription
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.
Scores
CVSS v3
6.2
EPSS
0.0032
EPSS Percentile
54.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-532
Status
published
Affected Products (3)
sendquick/entera_sms_gateway_firmware
sendquick/avera_sms_gateway_firmware
n/a/n/a
Timeline
Published
Feb 05, 2017
Tracked Since
Feb 18, 2026