CVE-2017-5137

MEDIUM

SendQuick Entera/Avera <2HF16 - Info Disclosure

Title source: llm

Description

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.

Scores

CVSS v3 6.2
EPSS 0.0032
EPSS Percentile 54.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-532
Status published

Affected Products (3)

sendquick/entera_sms_gateway_firmware
sendquick/avera_sms_gateway_firmware
n/a/n/a

Timeline

Published Feb 05, 2017
Tracked Since Feb 18, 2026