CVE-2017-5137

MEDIUM

SendQuick Entera/Avera <2HF16 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96031

Scores

CVSS v3 6.2
EPSS 0.0032
EPSS Percentile 54.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
sendquick/avera_sms_gateway_firmware
sendquick/entera_sms_gateway_firmware
Published Feb 05, 2017
Tracked Since Feb 18, 2026